• DocumentCode
    2960538
  • Title

    Application attack detection system (AADS): An anomaly based behavior analysis approach

  • Author

    Viswanathan, Ram Prasad ; Al-Nashif, Youssif ; Hariri, Salim

  • Author_Institution
    Dept. of ECE, Univ. of Arizona, Tucson, AZ, USA
  • fYear
    2011
  • fDate
    27-30 Dec. 2011
  • Firstpage
    150
  • Lastpage
    156
  • Abstract
    Network security, especially application layer security has gained importance with the rapid growth of web-based applications. Anomaly based approaches that profile the network traffic and look for abnormalities are effective against zero-day attacks. The complex nature of the web traffic, availability of multiple applications, privacy concerns and its own limitations make the development of such anomaly-based systems difficult. This paper proposes a framework for application layer anomaly detection. The framework uses a multiple model approach to detect anomalies. The framework encompasses a dedicated training phase to model the specific network traffic and a detection phase that can be deployed in real time. The framework has been applied to HTTP application traffic and multiple models have been developed. The experimental evaluation results of the AADS using multiple attack vectors have achieved a detection rate of almost 100%. In addition, the AADS has a false positive rate of 0.03%.
  • Keywords
    Internet; computer network security; telecommunication traffic; transport protocols; HTTP application traffic; Web traffic; Web-based applications; anomaly based behavior analysis; anomaly-based systems; application attack detection system; application layer anomaly detection; application layer security; attack vectors; detection phase; detection rate; network traffic; training phase; Buffer overflow; Data models; Databases; Monitoring; Particle separators; Payloads; Training; HTTP; anomaly; framework; multiple models; segregation;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Systems and Applications (AICCSA), 2011 9th IEEE/ACS International Conference on
  • Conference_Location
    Sharm El-Sheikh
  • ISSN
    2161-5322
  • Print_ISBN
    978-1-4577-0475-8
  • Electronic_ISBN
    2161-5322
  • Type

    conf

  • DOI
    10.1109/AICCSA.2011.6126606
  • Filename
    6126606