NESG

Icono Icono

Icono Icono

Measuring Normality in HTTP Traffic For Anomaly-Based Intrusion Detection

Juan Manuel Estévez Tapiador; Pedro García-Teodoro; Jesús Esteban Díaz Verdejo
Abstract:
In this paper, the problem of measuring normality in HTTP traffic for the purpose of anomaly-based network intrusion detection is addressed. The work carried out is expressed in two steps: first, some statistical analysis of both normal and hostile traffic is presented. The experimental results of this study reveal that certain features extracted from HTTP requests can be used to distinguish anomalous (and, therefore, suspicious) traffic from that corresponding to correct, normal connections. The second part of the paper presents a new anomaly-based approach to detect attacks carried out over HTTP traffic. The technique introduced is statistical and makes use of Markov chains to model HTTP network traffic. The incoming HTTP traffic is parameterised for evaluation on a packet payload basis. Thus, the payload of each HTTP request is segmented into a certain number of contiguous blocks, which are subsequently quantized according to a previously trained scalar codebook. Finally, the temporal sequence of the symbols obtained is evaluated by means of a Markov model derived during a training phase. The detection results provided by our approach show important improvements, both in detection ratio and regarding false alarms, in comparison with those obtained using other current techniques.
Research areas:
Year:
2004
Type of Publication:
Article
Journal:
Computer Networks
Volume:
45
Pages:
175-193
ISSN:
1389-1286
DOI:
10.1016/j.comnet.2003.12.016
Hits: 1864