Web Attack Payload Identification and Interpretability Analysis Based on Graph Convolutional Network

被引:0
|
作者
Xu, Yijia [1 ]
Fang, Yong [1 ]
Liu, Zhonglin [1 ]
机构
[1] Sichuan Univ, Cyber Sci & Engn Coll, Chengdu, Sichuan, Peoples R China
基金
中国国家自然科学基金;
关键词
Web attack; Payload detection; Graph embedding; Interpretability analysis;
D O I
10.1109/MSN57253.2022.00071
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Web attack payload identification is a significant part of the Web defense system. The current Web attack payload identification usually combines natural language processing and deep learning to automatically build a detection model to intercept malicious payloads. However, these detection methods ignore the bidirectional association between fields and is prone to the payload dilution problem for long strings. In addition, the weak interpretability of deep learning models makes it difficult for researchers to solve the problem of model pollution and adjust the model according to the prediction logic. Therefore, this paper proposes a new Web attack payload identification method based on Graph Convolutional Network (GCN), which can effectively extract Web payload features and help model interpretability analysis. The core of this method is to transform the text feature problem into a graph feature extraction problem and to understand the structure and content of the Web payload from the graph perspective. The method performs node embedding on the Web payload graph through GCN, then converts the embedding vector into a graph feature vector through a feature fusion method. The node ablation method is used to analyze malicious payloads' interpretability and calculate the predicted impact rate of nodes inside the graph structure. The experiments on the CSIC 2010 v2 HTTP dataset show that the method proposed in this paper has high accuracy for identifying Web attack payloads, and the node embedding of the Relational Graph Convolutional Network (RGCN) method is more suitable for identifying Web attack payloads than other GCN methods. The research results of the paper show that the model interpretability analysis based on the Web payload graph is reasonable and can effectively assist researchers in adjusting the model and preventing the problem of model pollution.
引用
收藏
页码:398 / 407
页数:10
相关论文
共 50 条
  • [1] GraphXSS: An efficient XSS payload detection approach based on graph convolutional network
    Liu, Zhonglin
    Fang, Yong
    Huang, Cheng
    Han, Jiaxuan
    [J]. Computers and Security, 2022, 114
  • [2] GraphXSS: An efficient XSS payload detection approach based on graph convolutional network
    Liu, Zhonglin
    Fang, Yong
    Huang, Cheng
    Han, Jiaxuan
    [J]. COMPUTERS & SECURITY, 2022, 114
  • [3] Payload-Based Web Attack Detection Using Deep Neural Network
    Jin, Xiaohui
    Cui, Baojiang
    Yang, Jun
    Cheng, Zishuai
    [J]. ADVANCES ON BROAD-BAND WIRELESS COMPUTING, COMMUNICATION AND APPLICATIONS, BWCCA-2017, 2018, 12 : 482 - 488
  • [4] Hierarchical Dynamic Graph Convolutional Network With Interpretability for EEG-Based Emotion Recognition
    Ye, Mengqing
    Chen, C. L. Philip
    Zhang, Tong
    [J]. IEEE TRANSACTIONS ON NEURAL NETWORKS AND LEARNING SYSTEMS, 2022, : 1 - 12
  • [5] Topology Identification of Microgrid Based on Graph Convolutional Network
    Sun, Wei
    Zhu, Shirui
    Yang, Jianping
    Zhu, Mengyu
    Li, Qiyue
    [J]. Dianli Xitong Zidonghua/Automation of Electric Power Systems, 2022, 46 (05): : 71 - 77
  • [6] IGCN: Infected Graph Convolutional Network based Source Identification
    Guo, Qiang
    Zhang, Chong
    Zhang, Haisong
    Fu, Luoyi
    [J]. 2021 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2021,
  • [7] Attack Group Analysis and Identification based on Heterogeneous Graph
    Han, Taehyun
    Hwang, Sangyeon
    Lee, Tae-jin
    [J]. 2024 SILICON VALLEY CYBERSECURITY CONFERENCE, SVCC 2024, 2024,
  • [8] Power Analysis Attack Based on Lightweight Convolutional Neural Network
    Li, Xiang
    Yang, Ning
    Chen, Aidong
    Liu, Weifeng
    Liu, Xiaoxiao
    Huang, Na
    [J]. FRONTIERS IN CYBER SECURITY, FCS 2022, 2022, 1726 : 105 - 118
  • [9] Space Target Material Identification Based on Graph Convolutional Neural Network
    Li, Na
    Gong, Chengeng
    Zhao, Huijie
    Ma, Yun
    [J]. REMOTE SENSING, 2023, 15 (07)
  • [10] Cooperative Attack Detection of Power CPS based on Feature Relation Graph Convolutional Network
    Li, Da
    Shang, Tao
    Gao, Xueqin
    Tang, Yao
    [J]. 2022 IEEE 19TH INTERNATIONAL CONFERENCE ON MOBILE AD HOC AND SMART SYSTEMS (MASS 2022), 2022, : 380 - 384