Title :
Detection of web server attacks using principles of immunocomputing
Author :
Kotov, Vadim D. ; Vasilyev, Vladimir I.
Author_Institution :
Dept. of Comput. Eng. & Inf. Security, Ufa State Aviation Tech. Univ., Ufa, Russia
Abstract :
A new approach to web server attacks detection based on the statistical analysis of HTTP requests and principles of immunocomputing is proposed in the paper. We use a set of legitimate HTTP requests as training data. Each request is represented as its byte frequency distribution. Immunocomputing is used to calculate the binding energy between the training data and sampled HTTP requests. If the binding energy is less than some threshold, an alarm will be triggered. Our approach has been tested with the DARPA data set and the data set collected from the vulnerable web server. We have shown that our approach detects various attacks with a high degree of accuracy.
Keywords :
Internet; artificial immune systems; security of data; statistical analysis; DARPA data set; HTTP request; Web server attack; binding energy; byte frequency distribution; immunocomputing; statistical analysis; training data; Computer crashes; Immune system; Information security; Silicon; Skin;
Conference_Titel :
Nature and Biologically Inspired Computing (NaBIC), 2010 Second World Congress on
Conference_Location :
Fukuoka
Print_ISBN :
978-1-4244-7377-9
DOI :
10.1109/NABIC.2010.5716269