Interleaving-Oriented Correlation Finding for Web Mimicry Attacks based on Conditional Random Fields

碩士 === 國立臺灣科技大學 === 資訊工程系 === 97 === Web mimicry attacks lead anomaly-based web application intrusion detection to be evaded through insertion of meaningless or irrelevant characters. In this study, we propose Interleaving-Oriented Correlation Finding (IOCF) in order to against the Web Mimicry attac...

Full description

Bibliographic Details
Main Authors: En-Sih Liou, 劉恩賜
Other Authors: Hanhn-Ming Lee
Format: Others
Language:en_US
Published: 2009
Online Access:http://ndltd.ncl.edu.tw/handle/51970792570403973910
id ndltd-TW-097NTUS5392082
record_format oai_dc
spelling ndltd-TW-097NTUS53920822016-05-02T04:11:47Z http://ndltd.ncl.edu.tw/handle/51970792570403973910 Interleaving-Oriented Correlation Finding for Web Mimicry Attacks based on Conditional Random Fields 應用條件隨機域進行插入導向前後關聯分析以辨識網站擬態攻擊 En-Sih Liou 劉恩賜 碩士 國立臺灣科技大學 資訊工程系 97 Web mimicry attacks lead anomaly-based web application intrusion detection to be evaded through insertion of meaningless or irrelevant characters. In this study, we propose Interleaving-Oriented Correlation Finding (IOCF) in order to against the Web Mimicry attacks. IOCF intends to segment HTTP requests into token sequences and models the token correlation in order to identify web mimicry attacks based on Conditional Random Fields (CRFs). CRFs is a widespread algorithm for solving sequence labeling problem and therefore robust for capturing the high dependency among different tokens in token sequence. Since CRF relaxes strong independence assumptions with previewed probabilistic sequence analysis methods (e.g. HMM), it is capable to capture long term dependency among observed sequences of token for improving the detection capability of Web Mimicry attacks. The proposed method just needs to inspect HTTP request, and is easier to plug in existing intrusion detection system for identifying subtle web attacks. The datasets are from “ECML/PKDD 2007’s Analyzing Web Traffic challenge”, public datasets for web application attacks detection for evaluation. The experimental result shows that the proposed system performs well in both web mimicry attacks and general web application attacks detection even in heavy interleaving cases. Hanhn-Ming Lee 李漢銘 2009 學位論文 ; thesis 63 en_US
collection NDLTD
language en_US
format Others
sources NDLTD
description 碩士 === 國立臺灣科技大學 === 資訊工程系 === 97 === Web mimicry attacks lead anomaly-based web application intrusion detection to be evaded through insertion of meaningless or irrelevant characters. In this study, we propose Interleaving-Oriented Correlation Finding (IOCF) in order to against the Web Mimicry attacks. IOCF intends to segment HTTP requests into token sequences and models the token correlation in order to identify web mimicry attacks based on Conditional Random Fields (CRFs). CRFs is a widespread algorithm for solving sequence labeling problem and therefore robust for capturing the high dependency among different tokens in token sequence. Since CRF relaxes strong independence assumptions with previewed probabilistic sequence analysis methods (e.g. HMM), it is capable to capture long term dependency among observed sequences of token for improving the detection capability of Web Mimicry attacks. The proposed method just needs to inspect HTTP request, and is easier to plug in existing intrusion detection system for identifying subtle web attacks. The datasets are from “ECML/PKDD 2007’s Analyzing Web Traffic challenge”, public datasets for web application attacks detection for evaluation. The experimental result shows that the proposed system performs well in both web mimicry attacks and general web application attacks detection even in heavy interleaving cases.
author2 Hanhn-Ming Lee
author_facet Hanhn-Ming Lee
En-Sih Liou
劉恩賜
author En-Sih Liou
劉恩賜
spellingShingle En-Sih Liou
劉恩賜
Interleaving-Oriented Correlation Finding for Web Mimicry Attacks based on Conditional Random Fields
author_sort En-Sih Liou
title Interleaving-Oriented Correlation Finding for Web Mimicry Attacks based on Conditional Random Fields
title_short Interleaving-Oriented Correlation Finding for Web Mimicry Attacks based on Conditional Random Fields
title_full Interleaving-Oriented Correlation Finding for Web Mimicry Attacks based on Conditional Random Fields
title_fullStr Interleaving-Oriented Correlation Finding for Web Mimicry Attacks based on Conditional Random Fields
title_full_unstemmed Interleaving-Oriented Correlation Finding for Web Mimicry Attacks based on Conditional Random Fields
title_sort interleaving-oriented correlation finding for web mimicry attacks based on conditional random fields
publishDate 2009
url http://ndltd.ncl.edu.tw/handle/51970792570403973910
work_keys_str_mv AT ensihliou interleavingorientedcorrelationfindingforwebmimicryattacksbasedonconditionalrandomfields
AT liúēncì interleavingorientedcorrelationfindingforwebmimicryattacksbasedonconditionalrandomfields
AT ensihliou yīngyòngtiáojiànsuíjīyùjìnxíngchārùdǎoxiàngqiánhòuguānliánfēnxīyǐbiànshíwǎngzhànnǐtàigōngjī
AT liúēncì yīngyòngtiáojiànsuíjīyùjìnxíngchārùdǎoxiàngqiánhòuguānliánfēnxīyǐbiànshíwǎngzhànnǐtàigōngjī
_version_ 1718254368253280256