RPAD: An Unsupervised HTTP Request Parameter Anomaly Detection Method

被引:1
|
作者
Sun, Yizhen [1 ]
Xie, Yiman [2 ]
Wang, Weiping [2 ]
Zhang, Shigeng [2 ]
Wu, Yuxi [1 ]
Feng, Jingchuan [1 ]
机构
[1] Hunan Elect Power Corp, State Grid Informat & Commun Co, Changsha, Hunan, Peoples R China
[2] Cent South Univ, Sch Comp Sci & Engn, Changsha, Hunan, Peoples R China
基金
中国国家自然科学基金;
关键词
Anomaly detection; HTTP request parameter; Unsupervised algorithm;
D O I
10.1109/TrustCom50675.2020.00163
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Web servers in the Internet are vulnerable to Web attacks. A general way to launch Web attacks is to carry attack payloads in HTTP request parameters, e.g. SQL Injection and XSS attacks. To detect Web attacks, a commonly used method is to detect anomalies in the request parameters by making regular-expression-based matching rules for the parameters based on known security threats. However, such methods cannot detect unknown anomalies well and they can also be easily bypassed by using techniques like transcoding. Moreover, existing anomaly detection methods are usually based on supervised learning methods that require a large number of high-quality labelled samples as training sets, which are difficult to obtain in real situations. In this paper, we propose an unsupervised HTTP Request Parameter Anomaly Detection method called RPAD. RPAD uses five features of HTTP request parameters to perform anomaly detection including type, length, number of tokens, encoding type and character feature. After extracting the five features, RPAD uses the DBSCAN algorithm to cluster the parameters of each target access request and outputs the outliers found in the clustering process as anomalies. We evaluate the performance of RPAD on several datasets from multiple real websites of a Cyber Security Company. The results indicate that RPAD is highly efficient in detecting deviating abnormal parameter values with an accuracy of 99%.
引用
收藏
页码:1216 / 1222
页数:7
相关论文
共 50 条
  • [31] RAMFAE: a novel unsupervised visual anomaly detection method based on autoencoder
    Zhongju Sun
    Jian Wang
    Yakun Li
    [J]. International Journal of Machine Learning and Cybernetics, 2024, 15 : 355 - 369
  • [32] An Iterative Method for Unsupervised Robust Anomaly Detection Under Data Contamination
    Kim, Minkyung
    Yu, Jongmin
    Kim, Junsik
    Oh, Tae-Hyun
    Choi, Jun Kyun
    [J]. IEEE TRANSACTIONS ON NEURAL NETWORKS AND LEARNING SYSTEMS, 2023, : 1 - 13
  • [33] Unsupervised and Ensemble-based Anomaly Detection Method for Network Security
    Yang, Donghun
    Hwang, Myunggwon
    [J]. 2022-14TH INTERNATIONAL CONFERENCE ON KNOWLEDGE AND SMART TECHNOLOGY (KST 2022), 2022, : 75 - 79
  • [34] RAMFAE: a novel unsupervised visual anomaly detection method based on autoencoder
    Sun, Zhongju
    Wang, Jian
    Li, Yakun
    [J]. INTERNATIONAL JOURNAL OF MACHINE LEARNING AND CYBERNETICS, 2024, 15 (02) : 355 - 369
  • [35] A New Interpretable Unsupervised Anomaly Detection Method Based on Residual Explanation
    Oliveira, David F. N.
    Vismari, Lucio F.
    Nascimento, Alexandre M.
    de Almeida Jr, Jorge R.
    Cugnasca, Paulo S.
    Camargo Jr, Joao B.
    Almeida, Leandro
    Gripp, Rafael
    Neves, Marcelo
    [J]. IEEE ACCESS, 2022, 10 : 1401 - 1409
  • [36] Unsupervised Log Anomaly Detection Method Based on Multi-Feature
    He, Shiming
    Deng, Tuo
    Chen, Bowen
    Sherratt, R. Simon
    Wang, Jin
    [J]. CMC-COMPUTERS MATERIALS & CONTINUA, 2023, 76 (01): : 517 - 541
  • [37] Versatile unsupervised anomaly detection method for RTE-based networks
    Sestito, Guilherme Serpa
    Turcato, Afonso Celso
    Dias, Andre Luis
    Ferrari, Paolo
    da Silva, Maira Martins
    [J]. EXPERT SYSTEMS WITH APPLICATIONS, 2022, 206
  • [38] Systematic serendipity: a test of unsupervised machine learning as a method for anomaly detection
    Giles, Daniel
    Walkowicz, Lucianne
    [J]. MONTHLY NOTICES OF THE ROYAL ASTRONOMICAL SOCIETY, 2019, 484 (01) : 834 - 849
  • [39] A Multi-Scale A Contrario method for Unsupervised Image Anomaly Detection
    Tailanian, Matias
    Muse, Pablo
    Pardo, Alvaro
    [J]. 20TH IEEE INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND APPLICATIONS (ICMLA 2021), 2021, : 179 - 184
  • [40] Hybrid Intrusion Detection System using an Unsupervised method for Anomaly-based Detection
    Bhadauria, Saumya
    Mohanty, Tamanna
    [J]. 2021 IEEE INTERNATIONAL CONFERENCE ON ADVANCED NETWORKS AND TELECOMMUNICATIONS SYSTEMS (IEEE ANTS), 2021,