Anomaly detection of malicious users' behaviors for web applications based on web logs
Anomaly detection of malicious users' behaviors for web applications based on web logs
复制标题
基于Web日志的Web应用恶意用户行为异常检测
DOI:
10.1109/icct.2017.8359854
复制
发表时间:
2017
期刊:
影响因子:
--
通讯作者:
Dandan Li
中科院分区:
文献类型:
--
作者:
Yang Gao;Yan Ma;Dandan Li
With more and more online services developed into web applications, security problems based on web applications become more serious now. Most intrusion detection systems are based on every single request to find the cyber-attack instead of users' behaviors, and these systems can only protect web application from known vulnerability rather than some zero-day attacks. In order to detect newly developed attacks, we analyze web logs from web servers and define users' behaviors to divide them into normal and malicious ones. The result shows that by using the feature of web resources to define users' behaviors, a higher accuracy rate and lower false alarm rate of intrusion detection can be obtained.