6533b7d6fe1ef96bd12663e4
RESEARCH PRODUCT
Detection of Anomalous HTTP Requests Based on Advanced N-gram Model and Clustering Techniques
Mikhail ZolotukhinTimo Hämäläinensubject
Set (abstract data type)n-gramResource (project management)Computer scienceServerAnomaly detectionIntrusion detection systemData miningWeb serviceCluster analysiscomputer.software_genrecomputerdescription
Nowadays HTTP servers and applications are some of the most popular targets for network attacks. In this research, we consider an algorithm for HTTP intrusions detection based on simple clustering algorithms and advanced processing of HTTP requests which allows the analysis of all queries at once and does not separate them by resource. The method proposed allows detection of HTTP intrusions in case of continuously updated web-applications and does not require a set of HTTP requests free of attacks to build the normal user behaviour model. The algorithm is tested using logs acquired from a large real-life web service and, as a result, all attacks from these logs are detected, while the number of false alarms remains zero.
year | journal | country | edition | language |
---|---|---|---|---|
2013-01-01 |