• DocumentCode
    2553306
  • Title

    Detection of web server attacks using principles of immunocomputing

  • Author

    Kotov, Vadim D. ; Vasilyev, Vladimir I.

  • Author_Institution
    Dept. of Comput. Eng. & Inf. Security, Ufa State Aviation Tech. Univ., Ufa, Russia
  • fYear
    2010
  • fDate
    15-17 Dec. 2010
  • Firstpage
    25
  • Lastpage
    30
  • Abstract
    A new approach to web server attacks detection based on the statistical analysis of HTTP requests and principles of immunocomputing is proposed in the paper. We use a set of legitimate HTTP requests as training data. Each request is represented as its byte frequency distribution. Immunocomputing is used to calculate the binding energy between the training data and sampled HTTP requests. If the binding energy is less than some threshold, an alarm will be triggered. Our approach has been tested with the DARPA data set and the data set collected from the vulnerable web server. We have shown that our approach detects various attacks with a high degree of accuracy.
  • Keywords
    Internet; artificial immune systems; security of data; statistical analysis; DARPA data set; HTTP request; Web server attack; binding energy; byte frequency distribution; immunocomputing; statistical analysis; training data; Computer crashes; Immune system; Information security; Silicon; Skin;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Nature and Biologically Inspired Computing (NaBIC), 2010 Second World Congress on
  • Conference_Location
    Fukuoka
  • Print_ISBN
    978-1-4244-7377-9
  • Type

    conf

  • DOI
    10.1109/NABIC.2010.5716269
  • Filename
    5716269