A hybrid web log based intrusion detection model

A hybrid web log based intrusion detection model
复制标题

DOI:
10.1109/ccis.2016.7790283
复制
发表时间:
2016-08
期刊:
2016 4th International Conference on Cloud Computing and Intelligence Systems (CCIS)
影响因子:
--
通讯作者:
Jing Yu;Dan Tao;Zhaowen Lin
Jing Yu;Dan Tao;Zhaowen Lin
中科院分区:
其他
文献类型:
--
作者:
Jing Yu;Dan Tao;Zhaowen Lin

文献摘要

被引文献

相似文献

针对Web应用的攻击是最严重的网络安全威胁之一。目前,基于Web的攻击是如此复杂,单一的检测方法无法科普不断涌现的攻击。基于此,本文将误用检测和异常检测有效地结合起来,提出了一种混合的Web日志入侵检测模型。考虑到Web日志请求中包含了大部分攻击特征,提出了一种提取HTTP请求特征向量的方法来区分用户的异常行为。特别地,我们使用K-均值聚类算法构建了一个正常的访问模型的请求特征向量的基础上。测试数据表明,与单一入侵检测模型相比,提出的混合入侵检测模型能有效提高检测率,降低误报率。
Attacks against web-based applications is one of the most serious network security threats. At present, web-based attacks are so complex that single detection method is unable to cope with the emerging attacks. Motivated by this, we efficiently merge both misuse detection and anomaly detection, and propose a hybrid model for web log intrusion detection. Considering that a web log request contains the majority of attack features, we propose a method to extract feature vectors of HTTP request to distinguish abnormal behaviors of users. Particularly, we construct a normal access model based on request feature vectors by using K-means clustering algorithm. The test data indicate that compared to single intrusion detection model, the hybrid intrusion detection model proposed can effectively improve the detection rate and reduce the false alarm rate.