A Distributed Deep Learning System for Web Attack Detection on Edge Devices

A Distributed Deep Learning System for Web Attack Detection on Edge Devices
复制标题

DOI:
10.1109/tii.2019.2938778
复制
发表时间:
2020-03-01
影响因子:
12.3
通讯作者:
Guizani, Mohsen
Guizani, Mohsen
中科院分区:
计算机科学1区
文献类型:
--
作者:
Tian, Zhihong;Luo, Chaochao;Guizani, Mohsen

文献摘要

被引文献

相似文献

随着物联网和云技术的发展,大量的物联网设备和传感器将大量数据传输到云数据中心进行进一步处理。基于云的计算和存储在为我们提供相当大的便利的同时,也给我们带来了许多安全问题,例如滥用信息收集和集中在云端的Web服务器。传统的入侵检测系统和Web应用防火墙与新的网络环境越来越不兼容,具有机器学习或深度学习的相关系统不断涌现。然而,云物联网系统增加了对网络服务器的攻击,因为数据集中化带来了更有吸引力的回报。在本文中,我们基于分布式深度学习,提出了一种利用 URL 分析的 Web 攻击检测系统。该系统旨在检测网络攻击并部署在边缘设备上。云在物联网边缘的范式中应对上述挑战。采用多个并发深度模型,增强系统的稳定性和更新的便捷性。我们使用两个并发深度模型在该系统上进行了实验,并使用多个数据集将该系统与现有系统进行了比较。实验结果表明,该系统在检测Web攻击方面具有99.410%的准确率、98.91%的真阳性率(TPR)和99.55%的正常请求检测率(DRN)。
With the development of Internet of Things (IoT) and cloud technologies, numerous IoT devices and sensors transmit huge amounts of data to cloud data centers for further processing. While providing us considerable convenience, cloud-based computing and storage also bring us many security problems, such as the abuse of information collection and concentrated web servers in the cloud. Traditional intrusion detection systems and web application firewalls are becoming incompatible with the new network environment, and related systems with machine learning or deep learning are emerging. However, cloud-IoT systems increase attacks against web servers, since data centralization carries a more attractive reward. In this article, based on distributed deep learning, we propose a web attack detection system that takes advantage of analyzing URLs. The system is designed to detect web attacks and is deployed on edge devices. The cloud handles the above challenges in the paradigm of the Edge of Things. Multiple concurrent deep models are used to enhance the stability of the system and the convenience in updating. We implemented experiments on the system with two concurrent deep models and compared the system with existing systems by using several datasets. The experimental results with 99.410% in accuracy, 98.91% in true positive rate (TPR), and 99.55% in detection rate of normal requests (DRN) demonstrate the system is competitive in detecting web attacks.