Web Server Attack Detection using Machine Learning

Web Server Attack Detection using Machine Learning
复制标题

使用机器学习检测 Web 服务器攻击

DOI:
--
复制
发表时间:
2020
期刊:
2020 International Conference on Cyber Warfare and Security (ICCWS)
影响因子:
--
通讯作者:
Umar Farooq
Umar Farooq
中科院分区:
--
文献类型:
--
作者:
S. Saleem;Muhammad Sheeraz;Muhammad Hanif;Umar Farooq

文献摘要

被引文献

相似文献

今天,每个组织都在利用Web应用程序扩展其业务,这是由于Web的高可访问性和简单的访问。随着网络使用的扩大,攻击的危险也随之增加。需要一个有效的监控软件,可以及时发现这些攻击。HTML、PHP和Java脚本用于网站开发,SQL广泛用于数据库管理。最常见的Web服务器攻击包括SQL注入、DOS(拒绝服务)和XSS(跨站脚本)。基于规则的入侵检测系统只对关键字和模式进行检测,无法检测到未知的攻击。提出了一种基于机器学习的Web服务器日志入侵检测模型。该模型检测特定日志是正常日志还是攻击日志,并指定攻击类型。Web服务器日志通过使用Apache WAMP服务器创建专用网络来生成和收集。
Today, every single organization is utilizing web applications for extension of its business as a result of the high accessibility of web and simple access. With the expansion of web use, the danger of attacks has increased likewise. An efficient monitoring software which can detect these attacks timely is required. HTML, PHP and Java script are used for websites development and SQL is used for database management extensively. Most common web server attacks include SQL injection, DOS (Denial of Service) and XSS (Cross Site Scripting). Rule based intrusion detection systems work on keywords and patterns and are unable to detect unknown attacks. This paper proposes machine learning based model for intrusion detection using web server logs. This model detects whether a specific log is normal or an attack log and also specifies the type of attack. Web server logs are generated and collected by creating a private network using an Apache WAMP server.