DocumentCode
2553306
Title
Detection of web server attacks using principles of immunocomputing
Author
Kotov, Vadim D. ; Vasilyev, Vladimir I.
Author_Institution
Dept. of Comput. Eng. & Inf. Security, Ufa State Aviation Tech. Univ., Ufa, Russia
fYear
2010
fDate
15-17 Dec. 2010
Firstpage
25
Lastpage
30
Abstract
A new approach to web server attacks detection based on the statistical analysis of HTTP requests and principles of immunocomputing is proposed in the paper. We use a set of legitimate HTTP requests as training data. Each request is represented as its byte frequency distribution. Immunocomputing is used to calculate the binding energy between the training data and sampled HTTP requests. If the binding energy is less than some threshold, an alarm will be triggered. Our approach has been tested with the DARPA data set and the data set collected from the vulnerable web server. We have shown that our approach detects various attacks with a high degree of accuracy.
Keywords
Internet; artificial immune systems; security of data; statistical analysis; DARPA data set; HTTP request; Web server attack; binding energy; byte frequency distribution; immunocomputing; statistical analysis; training data; Computer crashes; Immune system; Information security; Silicon; Skin;
fLanguage
English
Publisher
ieee
Conference_Titel
Nature and Biologically Inspired Computing (NaBIC), 2010 Second World Congress on
Conference_Location
Fukuoka
Print_ISBN
978-1-4244-7377-9
Type
conf
DOI
10.1109/NABIC.2010.5716269
Filename
5716269
Link To Document