Vis enkel innførsel

dc.contributor.authorTorrano-Gimenez, Carmen
dc.contributor.authorNguyen, Hai Thanh
dc.contributor.authorAlvarez, Gonzalo
dc.contributor.authorFranke, Katrin
dc.date.accessioned2019-10-15T08:04:26Z
dc.date.available2019-10-15T08:04:26Z
dc.date.created2012-09-05T09:29:32Z
dc.date.issued2012
dc.identifier.issn1939-0114
dc.identifier.urihttp://hdl.handle.net/11250/2622148
dc.description.abstractIn the detection of web attacks, it is necessary that Web Application Firewalls (WAFs) are effective, at the same time than efficient. In this paper, we propose a new methodology for web attack detection that enhances these two aspects of WAFs. It involves both feature construction and feature selection. For the feature construction phase, many professionals rely on their expert knowledge to define a set of important features, what normally leads to high and reliable attack detection rates. Nevertheless, it is a manual process and not quickly adaptive to the changing network environments. Alternatively, automatic feature construction methods (such as n-grams) overcome this drawback, but they provide unreliable results. Therefore, in this paper, we propose to combine expert knowledge with n-gram feature construction method for reliable and efficient web attack detection. However, the number of n-grams grows exponentially with n, which usually leads to high dimensionality problems. Hence, we propose to apply feature selection to reduce the number of redundant and irrelevant features. In particular, we study the recently proposed Generic Feature Selection (GeFS) measure, which has been successfully tested in intrusion detection systems. Additionally, we use several decision tree algorithms as classifiers of WAFs. The experiments are conducted on the publicly available ECML/PKDD 2007 dataset. The results show that the combination of expert knowledge and n-grams outperforms each separate technique and that the GeFS measure can greatly reduce the number of features, thus enhancing both the effectiveness and efficiency of WAFs.nb_NO
dc.description.abstractCombining expert knowledge with automatic feature extraction for reliable web attack detectionnb_NO
dc.language.isoengnb_NO
dc.publisherWileynb_NO
dc.titleCombining expert knowledge with automatic feature extraction for reliable web attack detectionnb_NO
dc.typeJournal articlenb_NO
dc.typePeer reviewednb_NO
dc.description.versionpublishedVersionnb_NO
dc.source.journalSecurity and Communication Networksnb_NO
dc.identifier.doi10.1002/sec.603
dc.identifier.cristin942374
dc.description.localcodeCopyright © 2012 John Wiley & Sons, Ltd. This is an Open Access article.nb_NO
cristin.unitcode194,63,30,0
cristin.unitnameInstitutt for informasjonssikkerhet og kommunikasjonsteknologi
cristin.ispublishedtrue
cristin.fulltextoriginal
cristin.qualitycode1


Tilhørende fil(er)

Thumbnail

Denne innførselen finnes i følgende samling(er)

Vis enkel innførsel