首页> 外文期刊>Computers & Security >SAD: web session anomaly detection based on parameter estimation
【24h】

SAD: web session anomaly detection based on parameter estimation

机译:SAD:基于参数估计的Web会话异常检测

获取原文
获取原文并翻译 | 示例

摘要

Web attacks are too numerous in numbers and serious in potential consequences for modern society to tolerate. Unfortunately, current generation signature-based intrusion detection systems (IDS) are inadequate, and security techniques such as firewalls or access control mechanisms do not work well when trying to secure web services. In this paper, we empirically demonstrate that the Bayesian parameter estimation method is effective in analyzing web logs and detecting anomalous sessions. When web attacks were simulated with Whisker software, Snort, a well-known IDS based on misuse detection, caught only slightly more than one third of web attacks. Our technique, session anomaly detection (SAD), on the other hand, detected nearly all such attacks without having to rely on attack signatures at all. SAD works by first developing normal usage profile and comparing the web logs, as they are generated, against the expected frequencies. Our research indicates that SAD has the potential of detecting previously unknown web attacks and that the proposed approach would play a key role in developing an integrated environment to provide secure and reliable web services.
机译:Web攻击的数量太多,严重的后果使现代社会无法忍受。不幸的是,当前的基于签名的入侵检测系统(IDS)不足,在尝试保护Web服务安全时,诸如防火墙或访问控制机制之类的安全技术无法很好地工作。在本文中,我们通过经验证明贝叶斯参数估计方法可有效地分析Web日志和检测异常会话。当使用Whisker软件模拟Web攻击时,基于误用检测的著名IDS Snort仅捕获了略多于三分之一的Web攻击。另一方面,我们的技术(会话异常检测(SAD))可以检测几乎所有此类攻击,而完全不必依赖攻击特征。 SAD的工作方式是首先开发正常使用情况配置文件,然后将生成的Web日志与预期频率进行比较。我们的研究表明,SAD具有检测以前未知的Web攻击的潜力,并且所提出的方法将在开发提供安全可靠的Web服务的集成环境中发挥关键作用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号