Detection of attack-targeted scans from the Apache HTTP Server access logs

Detection of attack-targeted scans from the Apache HTTP Server access logs
复制标题

从 Apache HTTP Server 访问日志中检测针对攻击的扫描

DOI:
10.1016/j.aci.2017.04.002
复制
发表时间:
2018
影响因子:
--
通讯作者:
E. Gul
E. Gul
中科院分区:
--
文献类型:
--
作者:
M. B. Seyyar;Ferhat Ozgur Catak;E. Gul

文献摘要

被引文献

相似文献

可以出于不同的目的访问web应用程序。一个网站有可能被普通用户作为正常(自然)访问,被爬虫、机器人、蜘蛛等为了索引目的而查看,最后被恶意用户在攻击之前进行探索性扫描。针对攻击的web扫描可以被视为潜在攻击的一个阶段,与传统检测方法相比,它可以导致更多的攻击检测。在这项工作中,我们提出了一种方法来检测面向攻击的扫描,并将其与其他类型的访问区分开来。在这种情况下,我们使用Apache(或ISS) web服务器的访问日志文件,并试图通过检查过去的数据来确定攻击情况。除了web扫描检测,我们还插入了一个规则集来检测SQL注入和XSS攻击。我们的方法已应用于样本数据集,并根据性能指标对结果进行了分析,以比较我们的方法和其他常用的检测技术。此外,还对实际系统的测井样本进行了各种测试。最后,对今后的发展提出了几点建议。
A web application could be visited for different purposes. It is possible for a web site to be visited by a regular user as a normal (natural) visit, to be viewed by crawlers, bots, spiders, etc. for indexing purposes, lastly to be exploratory scanned by malicious users prior to an attack. An attack targeted web scan can be viewed as a phase of a potential attack and can lead to more attack detection as compared to traditional detection methods. In this work, we propose a method to detect attack-oriented scans and to distinguish them from other types of visits. In this context, we use access log files of Apache (or ISS) web servers and try to determine attack situations through examination of the past data. In addition to web scan detections, we insert a rule set to detect SQL Injection and XSS attacks. Our approach has been applied on sample data sets and results have been analyzed in terms of performance measures to compare our method and other commonly used detection techniques. Furthermore, various tests have been made on log samples from real systems. Lastly, several suggestions about further development have been also discussed.