Title :
A clustering-based method for intrusion detection in web servers
Author :
Pereira, Hermano ; Jamhour, Edgard
Author_Institution :
PPGIA, Pontifical Catholic Univ. of Parana - PUCPR, Curitiba, Brazil
Abstract :
Today, intrusion detection systems (IDS) are indispensable to protect environments that provide information via Internet. In the present trend of self-organizing and self-protecting system, a special type of IDS that operates by non-supervised learning is an interesting approach. This type of IDS is able to extract models of behavior of the environment without the need of prior knowledge about attacks or signatures. One of the techniques used to create such models is data clustering, where patterns of data access are collected and grouped to create IDS rules. In this paper we focus on the development of a non-supervised IDS for protecting Web servers from attacks using malicious HTTP access patterns. We propose a heuristic method for assigning labels to groups considering simultaneously the source and the content of the HTTP requests. The proposed method is completely self-organized, and does not require configuration or signature updates to prepare the IDS to detect new forms of attacks. Our evaluation shows that the proposed method yield fewer false positive alerts when compared to similar non-supervised methods in the literature.
Keywords :
Internet; file servers; learning (artificial intelligence); security of data; self-adjusting systems; statistical analysis; transport protocols; HTTP access patterns; clustering-based method; data clustering; heuristic method; intrusion detection systems; nonsupervised IDS; nonsupervised learning; protecting Web servers; self-organizing system; self-protecting system; web servers; Clustering algorithms; Indexes; Intrusion detection; Measurement; Training; Web servers; Intrusion detection; anomaly-based detection; clustering; security;
Conference_Titel :
Telecommunications (ICT), 2013 20th International Conference on
Conference_Location :
Casablanca
Print_ISBN :
978-1-4673-6425-6
DOI :
10.1109/ICTEL.2013.6632070