@article{2004_Comnet_NormalityHTTPTraffic, author = "Juan Manuel Est{\'e}vez Tapiador and Garc{\'i}a-Teodoro, Pedro and Jes{\'u}s Esteban D{\'i}az Verdejo", abstract = "In this paper, the problem of measuring normality in HTTP traffic for the purpose of anomaly-based network intrusion detection is addressed. The work carried out is expressed in two steps: first, some statistical analysis of both normal and hostile traffic is presented. The experimental results of this study reveal that certain features extracted from HTTP requests can be used to distinguish anomalous (and, therefore, suspicious) traffic from that corresponding to correct, normal connections. The second part of the paper presents a new anomaly-based approach to detect attacks carried out over HTTP traffic. The technique introduced is statistical and makes use of Markov chains to model HTTP network traffic. The incoming HTTP traffic is parameterised for evaluation on a packet payload basis. Thus, the payload of each HTTP request is segmented into a certain number of contiguous blocks, which are subsequently quantized according to a previously trained scalar codebook. Finally, the temporal sequence of the symbols obtained is evaluated by means of a Markov model derived during a training phase. The detection results provided by our approach show important improvements, both in detection ratio and regarding false alarms, in comparison with those obtained using other current techniques.", doi = "10.1016/j.comnet.2003.12.016", issn = "1389-1286", journal = "Computer Networks", pages = "175-193", title = "{M}easuring {N}ormality in {HTTP} {T}raffic {F}or {A}nomaly-{B}ased {I}ntrusion {D}etection", url = "http://dl.acm.org/citation.cfm?id=1006340.1006347", volume = "45", year = "2004", }