Title :
Application attack detection system (AADS): An anomaly based behavior analysis approach
Author :
Viswanathan, Ram Prasad ; Al-Nashif, Youssif ; Hariri, Salim
Author_Institution :
Dept. of ECE, Univ. of Arizona, Tucson, AZ, USA
Abstract :
Network security, especially application layer security has gained importance with the rapid growth of web-based applications. Anomaly based approaches that profile the network traffic and look for abnormalities are effective against zero-day attacks. The complex nature of the web traffic, availability of multiple applications, privacy concerns and its own limitations make the development of such anomaly-based systems difficult. This paper proposes a framework for application layer anomaly detection. The framework uses a multiple model approach to detect anomalies. The framework encompasses a dedicated training phase to model the specific network traffic and a detection phase that can be deployed in real time. The framework has been applied to HTTP application traffic and multiple models have been developed. The experimental evaluation results of the AADS using multiple attack vectors have achieved a detection rate of almost 100%. In addition, the AADS has a false positive rate of 0.03%.
Keywords :
Internet; computer network security; telecommunication traffic; transport protocols; HTTP application traffic; Web traffic; Web-based applications; anomaly based behavior analysis; anomaly-based systems; application attack detection system; application layer anomaly detection; application layer security; attack vectors; detection phase; detection rate; network traffic; training phase; Buffer overflow; Data models; Databases; Monitoring; Particle separators; Payloads; Training; HTTP; anomaly; framework; multiple models; segregation;
Conference_Titel :
Computer Systems and Applications (AICCSA), 2011 9th IEEE/ACS International Conference on
Conference_Location :
Sharm El-Sheikh
Print_ISBN :
978-1-4577-0475-8
Electronic_ISBN :
2161-5322
DOI :
10.1109/AICCSA.2011.6126606