Design and Evaluation of a Resilient Web Integrity Protection Framework Using AI-Based Defacement Detection and Automated Recovery for Government Systems
编号:8
访问权限:仅限参会人
更新:2026-10-04 23:11:01 浏览:8次
Online
摘要
Protecting public-facing government websites requires distinguishing unauthorized modifications from legitimate administrative updates while preventing automated responses from erasing approved content. This study presents the design and controlled evaluation of a resilient web integrity protection framework that separates anomaly detection from authorization and recovery decisions. Developed through a design science research approach, the framework integrates content monitoring, deterministic integrity validation, advisory anomaly scoring, a policy-based safety gate, bounded restoration, and post-recovery verification. Four three-valued authorization checks assess identity, scope, approved-content consistency, and the permitted change window. Unresolved evidence requires human review without automatic rollback, while eligible unauthorized changes are restored through a single-use lease bound to a specific decision, asset, and baseline version. Evaluation used an isolated municipal tourism information prototype and a performance generation of 4,000 labeled event windows partitioned by source template into training, validation, and test sets. On 812 held-out test windows, the deterministic rule mode achieved precision, recall, and F1 scores of 1.000. The selected one-class support vector machine achieved precision of 0.942, recall of 0.377, and an F1 score of 0.538. The hybrid comparison added one false positive without improving recall, providing no observed incremental detection benefit under the tested conditions. Content restoration passed in all 1,520 attempts, whereas complete verification across content, database visibility, application health, rendered output, and peer convergence passed in 1,519 attempts because one rendered-output request timed out. The ninety-fifth-percentile detection latency was 5.357 seconds, exceeding the five-second target; corresponding gate and recovery latencies were 0.769 and 6.206 seconds. Separately, three raters inspected 239 packets from a 1,200-window generation. Original majority agreement with the answer key was 98.74%, increasing to 100% after targeted reassessment; this follow-up represents discrepancy resolution rather than independent validation of the performance generation. The findings support explicit separation of authorization evidence from anomaly scoring when automated recovery can affect legitimate content. The contribution is an evaluated recovery architecture and an empirical account of its limitations, rather than a new detection algorithm. Generalization remains bounded by trusted approval mechanisms, generated scenarios, restricted monitoring coverage, and three application processes sharing one host and repository.
关键词
Web defacement detection; authorization-aware integrity validation; safety-gated automated recovery; anomaly detection; cyber resilience.
稿件作者
ABRICAM TINGA
FEU Institute of Technology;La Consolacion University Philippines;FEU TECH
Ace Lagman
FEU INSTITUTE OF TECHNOLOGY MANILA
Isagani Tano
Quezon City Unversity
Joseph Espino
National University Baliwag
Jayson Batoon
La Consolacion University Philippines;Bulacan State University
Jonilo Mababa
La Consolacion University Philippines
Jovy Jay Cabrera
Immaculate Conception I-College Of Arts and Technology
发表评论