DocumentCode
3537071
Title
A clustering-based method for intrusion detection in web servers
Author
Pereira, Hermano ; Jamhour, Edgard
Author_Institution
PPGIA, Pontifical Catholic Univ. of Parana - PUCPR, Curitiba, Brazil
fYear
2013
fDate
6-8 May 2013
Firstpage
1
Lastpage
5
Abstract
Today, intrusion detection systems (IDS) are indispensable to protect environments that provide information via Internet. In the present trend of self-organizing and self-protecting system, a special type of IDS that operates by non-supervised learning is an interesting approach. This type of IDS is able to extract models of behavior of the environment without the need of prior knowledge about attacks or signatures. One of the techniques used to create such models is data clustering, where patterns of data access are collected and grouped to create IDS rules. In this paper we focus on the development of a non-supervised IDS for protecting Web servers from attacks using malicious HTTP access patterns. We propose a heuristic method for assigning labels to groups considering simultaneously the source and the content of the HTTP requests. The proposed method is completely self-organized, and does not require configuration or signature updates to prepare the IDS to detect new forms of attacks. Our evaluation shows that the proposed method yield fewer false positive alerts when compared to similar non-supervised methods in the literature.
Keywords
Internet; file servers; learning (artificial intelligence); security of data; self-adjusting systems; statistical analysis; transport protocols; HTTP access patterns; clustering-based method; data clustering; heuristic method; intrusion detection systems; nonsupervised IDS; nonsupervised learning; protecting Web servers; self-organizing system; self-protecting system; web servers; Clustering algorithms; Indexes; Intrusion detection; Measurement; Training; Web servers; Intrusion detection; anomaly-based detection; clustering; security;
fLanguage
English
Publisher
ieee
Conference_Titel
Telecommunications (ICT), 2013 20th International Conference on
Conference_Location
Casablanca
Print_ISBN
978-1-4673-6425-6
Type
conf
DOI
10.1109/ICTEL.2013.6632070
Filename
6632070
Link To Document