A novel framework for active detection of HTTP based attacks

Liang Jie*, Sun Jianwei, Hu Changzhen

*此作品的通讯作者

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

Web application vulnerabilities represent a substantial portion of the security exposures of computer networks. Considering HTTP protocol is stateless, we explore the effectiveness of HTTP-session model to effectively describe http behavior. Based on the HTTP-session model and the analysis of http attack behavior, we present a novel framework to actively detect http attacks. Our method takes http requests as input and calculates anomalous probability for each session attribute and for the session as a whole as output. All the probabilities are weighted and summed up to produce final probability, and this probability is used to decide whether http session is attack or not. We demonstrate the effectiveness of the proposed methods via simulation studies using real-world web access logs. Experiments prove that our detection framework achieves high detection rates under very few false positives.

源语言英语
主期刊名Communication Systems and Information Technology - Selected Papers from the 2011 International Conference on Electric and Electronics, EEIC 2011
411-418
页数8
版本VOL. 4
DOI
出版状态已出版 - 2011
活动2011 International Conference on Electric and Electronics, EEIC 2011 - Nanchang, 中国
期限: 20 6月 201122 6月 2011

出版系列

姓名Lecture Notes in Electrical Engineering
编号VOL. 4
100 LNEE
ISSN(印刷版)1876-1100
ISSN(电子版)1876-1119

会议

会议2011 International Conference on Electric and Electronics, EEIC 2011
国家/地区中国
Nanchang
时期20/06/1122/06/11

指纹

探究 'A novel framework for active detection of HTTP based attacks' 的科研主题。它们共同构成独一无二的指纹。

引用此