Title of article
Auto-Encoder LSTM Methods for Anomaly- Based Web Application Firewall
Author/Authors
Moradi Vartouni, Ali Faculty of Electrical and Computer Engineering - K.N. Toosi University of Technology, Tehran, Iran , Mehralian, Soheil Faculty of Electrical and Computer Engineering - K.N. Toosi University of Technology, Tehran, Iran , Teshnehlab, Mohammad Faculty of Electrical and Computer Engineering - K.N. Toosi University of Technology, Tehran, Iran , Sedighian Kashi, Saeed Faculty of Electrical and Computer Engineering - K.N. Toosi University of Technology, Tehran, Iran
Pages
8
From page
49
To page
56
Abstract
Web Application Firewall (WAF) is known as one of the Intrusion Detection System (IDS) solutions for
protecting web servers from HTTP attacks. WAF is a tool to identify and prevent many types of attacks, such as XSS
and SQL-injection. In this paper, deep machine learning algorithms are used for enriching the WAF based on the
anomaly detection method. Firstly, we construct attributes from HTTP data, to do so we consider two models namely
n-gram and one-hot. Then, according to Auto-Encoder LSTM (AE-LSTM) as an unsupervised deep leaning method,
we should extract informative features and then reduce them. Finally, we use ensemble isolation forest to train only
normal data for the classifier. We apply the proposed model on CSIC 2010 and ECML/ PKDD 2007 datasets. The
results show AE-LSTM has higher performance in terms of accuracy and generalization compared with naïve methods
on CSIC dataset; the proposed method also have acceptable detection rate on ECML/PKDD dataset using n-gram
model.
Keywords
Web Application Firewall , Anomaly Detection , LSTM , AE-LSTM , Ensemble Isolation Forest
Journal title
International Journal of Information and Communication Technology Research
Serial Year
2019
Record number
2546382
Link To Document