Detecting Malicious Behavior in Microservice Based Web Applications

被引:0
|
作者
Ozbek, Mustafa [1 ]
Sandikkaya, Mehmet Tahir [1 ]
机构
[1] Istanbul Tech Univ, Comp Engn Dept, TR-34469 Istanbul, Turkey
关键词
Malicious Behavior; Web Attacks; Microservice; Machine learning; Web Application; Data Classification;
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Not only the increased complexity of the malicious acts on the Internet, but also the continuous increase of new attack methods compromise Internet-based services as a threat to the modern society. In this study, malicious behavior in a microservices-based web application is detected by measuring the patterns of CRUD (create, read, update, delete) access. The aim of this paper is to detect malicious users (or even the first malicious attempt of a trustworthy user) as soon as the action occurred according to the characteristics of the sequential use of microservices. The proposed approach renders OWASP Foundation's Top 10 critical web application security risks as possible attack vectors. Thus, a data set including such attacks together with mostly benign behavior is generated and measured on the microservices-based web application. The data set is then used to determine benign and malicious classes of behavior using RandomForest, NaiveBayes, J48, AdaBoost, ZeroR, Bagging, Logistic Regression and K-Star machine learning algorithms. The best malicious behavior detection accuracy encountered during experiments is an auspicious 99.36% using RandomForest classification algorithm. After the classification of malicious behavior, the respective user's further access to the microservices could be blocked to prevent the waste of resources.
引用
收藏
页数:4
相关论文
共 50 条
  • [21] Detecting Malicious Behaviors in Java']JavaScript Applications
    Mao, Jian
    Bian, Jingdong
    Bai, Guangdong
    Wang, Ruilong
    Chen, Yue
    Xiao, Yinhao
    Liang, Zhenkai
    [J]. IEEE ACCESS, 2018, 6 : 12284 - 12294
  • [22] An Unsupervised-Learning Based Method for Detecting Groups of Malicious Web Crawlers in Internet
    Yue, Tianyi
    Zhou, Yadong
    Hu, Bowen
    Xu, Zhanbo
    Guan, Xiaohong
    Zhou, Hao
    Liu, Ting
    [J]. 2021 IEEE 17TH INTERNATIONAL CONFERENCE ON AUTOMATION SCIENCE AND ENGINEERING (CASE), 2021, : 367 - 372
  • [23] Detecting DoS Attacks in Microservice Applications: Approach and Case Study
    Castro, Jessica
    Laranjeiro, Nuno
    Vieira, Marco
    [J]. PROCEEDINGS OF 2022 11TH LATIN-AMERICAN SYMPOSIUM ON DEPENDABLE COMPUTING, LADC 2022, 2022, : 73 - 78
  • [24] MaGiC: a DSL Framework for Implementing Language Agnostic Microservice-based Web Applications
    Bucchiarone, Antonio
    Ciumedean, Claudiu
    Soysal, Kemal
    Dragoni, Nicola
    Pech, Vaclav
    [J]. JOURNAL OF OBJECT TECHNOLOGY, 2023, 22 (01): : 1 - 21
  • [25] Lino - An Intelligent System for Detecting Malicious Web-Robots
    Grzinic, Toni
    Mrsic, Leo
    Saban, Josip
    [J]. INTELLIGENT INFORMATION AND DATABASE SYSTEMS, PT II, 2015, 9012 : 559 - 568
  • [26] Detecting Malicious Web Scraping Activity: a Study with Diverse Detectors
    Marques, Pedro
    Dabbabi, Zayani
    Mironescu, Miruna-Mihaela
    Thonnard, Olivier
    Bessani, Alysson
    Buontempo, Frances
    Gashi, Ilir
    [J]. 2018 IEEE 23RD PACIFIC RIM INTERNATIONAL SYMPOSIUM ON DEPENDABLE COMPUTING (PRDC), 2018, : 269 - 278
  • [27] Using Diverse Detectors for Detecting Malicious Web Scraping Activity
    Marques, Pedro
    Dabbabi, Zayani
    Mironescu, Miruna-Mihaela
    Thonnard, Olivier
    Bessani, Alysson
    Buontempo, Frances
    Gashi, Ilir
    [J]. 2018 48TH ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS WORKSHOPS (DSN-W), 2018, : 67 - 68
  • [28] INDAGO: A New Framework For Detecting Malicious SDN Applications
    Lee, Chanhee
    Yoon, Changhoon
    Shin, Seungwon
    Cha, Sang Kil
    [J]. 2018 IEEE 26TH INTERNATIONAL CONFERENCE ON NETWORK PROTOCOLS (ICNP), 2018, : 220 - 230
  • [29] Detecting Malicious Behavior in a Vehicular DTN for Public Transportation
    Guo, Yinghui
    Schildt, Sebastian
    Poegel, Tobias
    Wolf, Lars
    [J]. 2013 GLOBAL INFORMATION INFRASTRUCTURE SYMPOSIUM, 2013,
  • [30] Detecting Malicious Behavior and Collusion for Online Rating System
    Cao, Liu
    Sun, Yuqing
    Wang, Shaoqing
    Li, Mingzhu
    [J]. 2016 IEEE TRUSTCOM/BIGDATASE/ISPA, 2016, : 1046 - 1053