• DocumentCode
    2902781
  • Title

    Detecting Anomalous Web Browsing via Diffusion Wavelets

  • Author

    Suen, Ho Yan ; Lau, Wing Cheong ; Yue, OnChing

  • Author_Institution
    Dept. of Inf. Eng., Chinese Univ. of Hong Kong, Hong Kong, China
  • fYear
    2010
  • fDate
    23-27 May 2010
  • Firstpage
    1
  • Lastpage
    6
  • Abstract
    Web access logs contain information which can be converted to represent the access history of individual users. A large number of essential attributes can be extracted from the access history. For example, the access counts of each webpage, the occurrence of different webpage access sequences and the time spent between consecutive accesses. Each of the above attributes represents a dimension in the feature space, and all the attributes together form a very high dimension space. Diffusion Wavelets can efficiently project the high dimensional data onto a low-dimensional space according to the correlations between various attributes, so that common anomaly detection algorithms can be applied. In this paper, we propose a system which leverages this technique to differentiate web-access requests generated by Denial of Service (DoS) attacks from legitimate ones. We demonstrate the effectiveness of the proposed system via simulation studies using real-world web access logs. For a simulated HTTP flooding attack which creates a 1000% overload at the web-server, the proposed scheme can reduce the ratio of the attack-to-legitimate requests admitted by the server from 200:1 to 30:1 so that more than 55% of the legitimate requests can still receive proper services under such a severe DoS attack.
  • Keywords
    Internet; security of data; HTTP flooding attack; Web access logs; Webpage access sequences; anomalous Web browsing detection; denial-of-service attack; diffusion wavelets; Communications Society; Computer crime; Data mining; Detection algorithms; Floods; History; Length measurement; Navigation; Wavelet analysis; Web server;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Communications (ICC), 2010 IEEE International Conference on
  • Conference_Location
    Cape Town
  • ISSN
    1550-3607
  • Print_ISBN
    978-1-4244-6402-9
  • Type

    conf

  • DOI
    10.1109/ICC.2010.5502089
  • Filename
    5502089