• DocumentCode
    2834613
  • Title

    A framework for detecting anomalies in HTTP traffic using instance-based learning and k-nearest neighbor classification

  • Author

    Kirchner, Michael

  • Author_Institution
    Dept. Secure Inf. Syst., Upper Austria Univ. of Appl. Sci., Hagenberg, Austria
  • fYear
    2010
  • fDate
    26-28 May 2010
  • Firstpage
    1
  • Lastpage
    8
  • Abstract
    Attacks against web applications and web-based services that use HTTP as a communication protocol pose a serious threat to today´s information technology infrastructures. A common countermeasure is to apply misuse detection and prevention systems that compare the contents of HTTP traffic against signatures of known attacks, as it is for example done by web application firewalls. A serious drawback of these systems is the fact that the used signatures often are not tailored for the individual web applications to be protected. Furthermore, signatures can often be circumvented by rewriting attacks into different forms, resulting in successful exploitation and circumvention of a misuse detection or prevention system. This paper presents the design and implementation of an anomaly detection framework for HTTP traffic that operates without signatures of known attacks. It rather learns normal usage patterns of web-based applications by inspecting full HTTP request and response contents. The results are then used for anomaly detection. The framework automatically adjusts to the applications to be monitored, derives normal usage patterns and compares subsequent HTTP traffic to the built knowledge base.
  • Keywords
    Internet; learning (artificial intelligence); pattern classification; security of data; HTTP traffic; Web application firewalls; Web applications; Web-based services; anomaly detection; instance-based learning; k-nearest neighbor classification; misuse detection system; misuse prevention system; Computerized monitoring; Condition monitoring; Information systems; Information technology; Java; Pattern analysis; Protection; Protocols; Testing; Web server;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Security and Communication Networks (IWSCN), 2010 2nd International Workshop on
  • Conference_Location
    Karlstad
  • Print_ISBN
    978-1-4244-6938-3
  • Electronic_ISBN
    978-1-4244-6939-0
  • Type

    conf

  • DOI
    10.1109/IWSCN.2010.5497997
  • Filename
    5497997