6533b7d6fe1ef96bd12663e4

RESEARCH PRODUCT

Detection of Anomalous HTTP Requests Based on Advanced N-gram Model and Clustering Techniques

Mikhail ZolotukhinTimo Hämäläinen

subject

Set (abstract data type)n-gramResource (project management)Computer scienceServerAnomaly detectionIntrusion detection systemData miningWeb serviceCluster analysiscomputer.software_genrecomputer

description

Nowadays HTTP servers and applications are some of the most popular targets for network attacks. In this research, we consider an algorithm for HTTP intrusions detection based on simple clustering algorithms and advanced processing of HTTP requests which allows the analysis of all queries at once and does not separate them by resource. The method proposed allows detection of HTTP intrusions in case of continuously updated web-applications and does not require a set of HTTP requests free of attacks to build the normal user behaviour model. The algorithm is tested using logs acquired from a large real-life web service and, as a result, all attacks from these logs are detected, while the number of false alarms remains zero.

https://doi.org/10.1007/978-3-642-40316-3_33