DocumentCode
166405
Title
Distinguishing between Web Attacks and Vulnerability Scans Based on Behavioral Characteristics
Author
Goseva-Popstojanova, Katerina ; Dimitrijevikj, Ana
Author_Institution
Lane Dept. of Comput. Sci. & Electr. Eng., West Virginia Univ., Morgantown, WV, USA
fYear
2014
fDate
13-16 May 2014
Firstpage
42
Lastpage
48
Abstract
The number of vulnerabilities and reported attacks on Web systems are showing increasing trends, which clearly illustrate the need for better understanding of malicious cyber activities. In this paper we use clustering to classify attacker activities aimed at Web systems. The empirical analysis is based on four datasets, each in duration of several months, collected by high-interaction honey pots. The results show that behavioral clustering analysis can be used to distinguish between attack sessions and vulnerability scan sessions. However, the performance heavily depends on the dataset. Furthermore, the results show that attacks differ from vulnerability scans in a small number of features (i.e., session characteristics). Specifically, for each dataset, the best feature selection method (in terms of the high probability of detection and low probability of false alarm) selects only three features and results into three to four clusters, significantly improving the performance of clustering compared to the case when all features are used. The best subset of features and the extent of the improvement, however, also depend on the dataset.
Keywords
Internet; computer network security; Web attacks; Web systems; behavioral characteristics; behavioral clustering analysis; feature selection method; high-interaction honey pots; malicious cyber activities; vulnerability scans; Blogs; Encyclopedias; Feature extraction; Radio access networks; Support vector machines; Web 2.0; Web applications; attacks; classification of malicious cyber activities; honeypots; vulnerability scans;
fLanguage
English
Publisher
ieee
Conference_Titel
Advanced Information Networking and Applications Workshops (WAINA), 2014 28th International Conference on
Conference_Location
Victoria, BC
Print_ISBN
978-1-4799-2652-7
Type
conf
DOI
10.1109/WAINA.2014.15
Filename
6844611
Link To Document