RPAD: An Unsupervised HTTP Request Parameter Anomaly Detection Method

被引:1
|
作者
Sun, Yizhen [1 ]
Xie, Yiman [2 ]
Wang, Weiping [2 ]
Zhang, Shigeng [2 ]
Wu, Yuxi [1 ]
Feng, Jingchuan [1 ]
机构
[1] Hunan Elect Power Corp, State Grid Informat & Commun Co, Changsha, Hunan, Peoples R China
[2] Cent South Univ, Sch Comp Sci & Engn, Changsha, Hunan, Peoples R China
基金
中国国家自然科学基金;
关键词
Anomaly detection; HTTP request parameter; Unsupervised algorithm;
D O I
10.1109/TrustCom50675.2020.00163
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Web servers in the Internet are vulnerable to Web attacks. A general way to launch Web attacks is to carry attack payloads in HTTP request parameters, e.g. SQL Injection and XSS attacks. To detect Web attacks, a commonly used method is to detect anomalies in the request parameters by making regular-expression-based matching rules for the parameters based on known security threats. However, such methods cannot detect unknown anomalies well and they can also be easily bypassed by using techniques like transcoding. Moreover, existing anomaly detection methods are usually based on supervised learning methods that require a large number of high-quality labelled samples as training sets, which are difficult to obtain in real situations. In this paper, we propose an unsupervised HTTP Request Parameter Anomaly Detection method called RPAD. RPAD uses five features of HTTP request parameters to perform anomaly detection including type, length, number of tokens, encoding type and character feature. After extracting the five features, RPAD uses the DBSCAN algorithm to cluster the parameters of each target access request and outputs the outliers found in the clustering process as anomalies. We evaluate the performance of RPAD on several datasets from multiple real websites of a Cyber Security Company. The results indicate that RPAD is highly efficient in detecting deviating abnormal parameter values with an accuracy of 99%.
引用
收藏
页码:1216 / 1222
页数:7
相关论文
共 50 条
  • [1] Data mining methods for anomaly detection of HTTP request exploitations
    Wang, XF
    Zhou, JL
    Yu, SS
    Cai, LZ
    [J]. FUZZY SYSTEMS AND KNOWLEDGE DISCOVERY, PT 2, PROCEEDINGS, 2005, 3614 : 320 - 323
  • [2] Evaluation of HTTP request anomaly detection model using fastText and convolutional autoencoder
    Yamada, Haruta
    Kawahara, Ryoichi
    [J]. IEICE COMMUNICATIONS EXPRESS, 2024, 13 (07): : 240 - 243
  • [3] Web Application Anomaly Detection Based On Converting HTTP Request Parameters To Numeric
    Huynh Hoang Tan
    Tran Van Hoai
    [J]. 2021 15TH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING AND APPLICATIONS (ACOMP 2021), 2021, : 93 - 97
  • [4] Semi-unsupervised Machine Learning for Anomaly Detection in HTTP Traffic
    Kozik, Rafal
    Choras, Michal
    Renk, Rafal
    Holubowicz, Witold
    [J]. PROCEEDINGS OF THE 9TH INTERNATIONAL CONFERENCE ON COMPUTER RECOGNITION SYSTEMS, CORES 2015, 2016, 403 : 767 - 775
  • [5] Patterns Extraction Method for Anomaly Detection in HTTP Traffic
    Kozik, Rafal
    Choras, Michal
    Renk, Rafal
    Holubowicz, Witold
    [J]. INTERNATIONAL JOINT CONFERENCE: CISIS'15 AND ICEUTE'15, 2015, 369 : 227 - 236
  • [6] Unsupervised Nonparametric Anomaly Detection: A Kernel Method
    Zou, Shaofeng
    Liang, Yingbin
    Poor, H. Vincent
    Shi, Xinghua
    [J]. 2014 52ND ANNUAL ALLERTON CONFERENCE ON COMMUNICATION, CONTROL, AND COMPUTING (ALLERTON), 2014, : 836 - 841
  • [7] Sequential Ensemble Method for Unsupervised Anomaly Detection
    Huy Van Nguyen
    Trung Thanh Nguyen
    Quang Uy Nguyen
    [J]. 2017 9TH INTERNATIONAL CONFERENCE ON KNOWLEDGE AND SYSTEMS ENGINEERING (KSE 2017), 2017, : 71 - 76
  • [8] An Effective Unsupervised Network Anomaly Detection Method
    Bhuyan, Monowar H.
    Bhattacharyya, D. K.
    Kalita, J. K.
    [J]. PROCEEDINGS OF THE 2012 INTERNATIONAL CONFERENCE ON ADVANCES IN COMPUTING, COMMUNICATIONS AND INFORMATICS (ICACCI'12), 2012, : 533 - 539
  • [9] Unsupervised Online Anomaly Detection With Parameter Adaptation for KPI Abrupt Changes
    Yu, Guang
    Cai, Zhiping
    Wang, Siqi
    Chen, Haiwen
    Liu, Fang
    Liu, Anfeng
    [J]. IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2020, 17 (03): : 1294 - 1308
  • [10] Online and Scalable Unsupervised Network Anomaly Detection Method
    Dromard, Juliette
    Roudiere, Gilles
    Owezarski, Philippe
    [J]. IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2017, 14 (01): : 34 - 47