Anomaly detection of malicious users' behaviors for web applications based on web logs

Anomaly detection of malicious users' behaviors for web applications based on web logs
复制标题

基于Web日志的Web应用恶意用户行为异常检测

DOI:
10.1109/icct.2017.8359854
复制
发表时间:
2017
期刊:
International Conference on Speech Technology and Human-Computer Dialogue
影响因子:
--
通讯作者:
Dandan Li
Dandan Li
中科院分区:
--
文献类型:
--
作者:
Yang Gao;Yan Ma;Dandan Li

文献摘要

被引文献

相似文献

随着越来越多的在线服务发展成为Web应用,基于Web应用的安全问题也日益突出。大多数入侵检测系统都是基于每一个请求来发现网络攻击,而不是用户的行为,这些系统只能保护Web应用程序免受已知的漏洞,而不是一些零日攻击。为了检测新开发的攻击,我们分析Web服务器的Web日志,并定义用户的行为,将其分为正常和恶意的。实验结果表明,利用Web资源的特征来定义用户行为,可以获得较高的入侵检测准确率和较低的误报率。
With more and more online services developed into web applications, security problems based on web applications become more serious now. Most intrusion detection systems are based on every single request to find the cyber-attack instead of users' behaviors, and these systems can only protect web application from known vulnerability rather than some zero-day attacks. In order to detect newly developed attacks, we analyze web logs from web servers and define users' behaviors to divide them into normal and malicious ones. The result shows that by using the feature of web resources to define users' behaviors, a higher accuracy rate and lower false alarm rate of intrusion detection can be obtained.