Visualizing web server attacks: patterns in PHPIDS logs

被引:5
|
作者
Alsaleh, Mansour [1 ]
Alarifi, Abdulrahman [1 ]
Alqahtani, Abdullah [2 ]
Al-Salman, AbdulMalik [2 ]
机构
[1] King Abdulaziz City Sci & Technol, Comp Res Inst, Riyadh, Saudi Arabia
[2] King Saud Univ, Dept Comp Sci, Riyadh, Saudi Arabia
关键词
security data visualization; log visualization; intrusion detection systems; network monitoring; web server attacks;
D O I
10.1002/sec.1147
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The prevalence and severity of application-layer vulnerabilities increase dramatically their corresponding attacks. In this paper, we present an extension to PHPIDS, an open source intrusion detection and prevention system for PHP-based web applications, to visualize its security log. Our usage of security data visualization is motivated by the fact that most security defense systems are mainly based on text-based logs for recording security-related events, which are difficult to analyze and correlate. The proposed extension analyzes PHPIDS logs, correlates these logs with the corresponding web server logs, and plots the security-related events. We use a set of tightly coupled visual representations of hypertext transfer protocol server requests containing known and suspicious malicious content, to provide system administrators and security analysts with fine-grained visual-based querying capabilities. We present multiple case studies to demonstrate the ability of our PHPIDS visualization extension to support security analysts with analytic reasoning and decision making in response to ongoing web server attacks. Experimenting the proposed PHPIDS visualization extension on real-world datasets shows promise for providing complementary information for effective situational awareness. Copyright (c) 2014 John Wiley & Sons, Ltd.
引用
收藏
页码:1991 / 2003
页数:13
相关论文
共 50 条
  • [1] Custom analysis of web server logs
    Passin, TB
    [J]. 17TH INTERNATIONAL CONFERENCE ON INTERACTIVE INFORMATION AND PROCESSING SYSTEMS (IIPS) FOR METEOROLOGY, OCEANOGRAPHY, AND HYDROLOGY, 2001, : 409 - 412
  • [2] Advanced techniques for analyzing web server logs
    Haffner, EG
    Roth, U
    Heuer, A
    Engel, T
    Meinel, C
    [J]. IC'2000: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON INTERNET COMPUTING, 2000, : 71 - 77
  • [3] Identifying and analyzing web server attacks
    Seifert, Christian
    Endicott-Popovsky, Barbara
    Frincke, Deborah
    Komisarczuk, Peter
    Muschevici, Radu
    Welch, Ian
    [J]. IFIP Advances in Information and Communication Technology, 2008, (151-161) : 151 - 161
  • [4] Identifying and analyzing web server attacks
    Seifert, Christian
    Endicott-Popovsky, Barbara
    Frincke, Deborah
    Komisarczuk, Peter
    Muschevici, Radu
    Welch, Ian
    [J]. ADVANCES IN DIGITAL FORENSICS IV, 2008, 285 : 151 - +
  • [5] Mining Web Server Logs for Creating Workload Models
    Abbors, Fredrik
    Truscan, Dragos
    Ahmad, Tanwir
    [J]. SOFTWARE TECHNOLOGIES, ICSOFT 2014, 2015, 555 : 131 - 150
  • [6] Combined mining of Web server logs and web contents for classifying user navigation patterns and predicting users' future requests
    Liu, Haibin
    Keselj, Vlado
    [J]. DATA & KNOWLEDGE ENGINEERING, 2007, 61 (02) : 304 - 330
  • [7] Studying Ransomware Attacks Using Web Search Logs
    Bansal, Chetan
    Deligiannis, Pantazis
    Maddila, Chandra
    Rao, Nikitha
    [J]. PROCEEDINGS OF THE 43RD INTERNATIONAL ACM SIGIR CONFERENCE ON RESEARCH AND DEVELOPMENT IN INFORMATION RETRIEVAL (SIGIR '20), 2020, : 1517 - 1520
  • [8] Detection of Server-side Web Attacks
    Corona, Igino
    Giacinto, Giorgio
    [J]. PROCEEDINGS OF THE FIRST WORKSHOP ON APPLICATIONS OF PATTERN ANALYSIS, 2010, 11 : 160 - 166
  • [9] Analyzing and Visualizing Web Server Access Log File
    Minh-Tri Nguyen
    Thanh-Dang Diep
    Tran Hoang Vinh
    Nakajima, Takuma
    Nam Thoai
    [J]. FUTURE DATA AND SECURITY ENGINEERING, FDSE 2018, 2018, 11251 : 349 - 367
  • [10] Effectively capturing user navigation paths in the Web using Web server logs
    Caldera, A
    Deshpande, Y
    [J]. WEB ENGINEERING, PROCEEDINGS, 2005, 3579 : 63 - 68