【24h】

INTRUSION DETECTION FOR WEB SERVER USING SSVM

机译:使用SSVM的Web服务器入侵检测

获取原文

摘要

We propose a network-based intrusion detectionsystem (NIDS) for detecting attacks on Microsoft IIS webserver. The classifier used in the system is based on smoothsupport vector machine (SSVM). Since SSVM is a binaryclassifier, in order to recognize attacks we use hierarchicalSSVMs. The NIDS captures HTTP request packet, andderives features from payload but header information. Byexperiments, the NIDS captured 27,654 HTTP requestpackets on-line, consisting of 15,517 normal and 12,137abnormal packets, the true positive rate is 99.23% and thefalse alarm instance is zero. Experimental results also showthat our NIDS can detect unknown or novel attack from64.90% to 97.20%, depending on their signatures variation.Moreover, our NIDS takes only 6.5×10-4 second in averagefor processing an incoming packet in a PC with 2.4GHZCPU and 256MB RAM.
机译:我们提出了一种基于网络的入侵检测系统(NIDS),用于检测对Microsoft IIS Web服务器的攻击。系统中使用的分类器基于平滑支持向量机(SSVM)。由于SSVM是二进制分类器,因此为了识别攻击,我们使用分层SSVM。 NIDS捕获HTTP请求数据包,并从有效负载中提取特征,但从标头信息中得出。通过实验,NIDS在线捕获了27,654个HTTP请求数据包,其中包括15,517个正常数据包和12,137个异常数据包,其真实阳性率为99.23%,错误警报实例为零。实验结果还表明,我们的NIDS可以根据特征变化从64.90%到97.20%范围内检测未知或新颖的攻击。此外,我们的NIDS在处理2.4GHZCPU的PC上平均仅需要6.5×10-4秒来处理传入数据包和256MB RAM。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号