维普中文期刊产品整合服务

An adaptive system for detecting malicious queries in web attacks

查看全文 作  者:Ying [1]DONG;Yuqing [1,2]ZHANG;Hua [2,3]MA;Qianru [4]WU;Qixu [1,2]LIU;Kai [5]WANG;Wenjie [1]WANG 高影响力作者 机构地区:[1]National Computer Network Intrusion Protection Center, University of Chinese Academy of Sciences;[2]State Key Laboratory of Information Security, Institute of Information Engineering,Chinese Academy of Sciences;[3]School of Mathematics and Statistics, Xidian University;[4]Security Department,Alibaba Group;[5]Zhanlu Laboratory, Tencent Incorporation高影响力机构 出  处:《Science China(Information Sciences)》索引2018年第61卷第3期,共16页高影响力期刊 基  金:supported in part by National Key Reasearch and Development Program of China (Grant No. 2016YFB0800703);in part by National Natural Science Foundation of China (Grant Nos. 61272481, 61572460);in part by Open Project Program of the State Key Laboratory of Information Security (Grant Nos. 2017-ZD-01, 2016-MS-02);in part by National Information Security Special Project of the National Development and Reform Commission of China (Grant No. (2012)1424) 摘  要:Web request query strings(queries), which pass parameters to a referenced resource, are always manipulated by attackers to retrieve sensitive data and even take full control of victim web servers and web applications. However, existing malicious query detection approaches in the literature cannot cope with changing web attacks. In this paper, we introduce a novel adaptive system(AMOD) that can adaptively detect web-based code injection attacks, which are the majority of web attacks, by analyzing queries. We also present a new adaptive learning strategy, called SVM HYBRID, leveraged by our system to minimize manual work. In the evaluation, an up-to-date detection model is trained on a ten-day query dataset collected from an academic institute's web server logs. The evaluation shows our approach overwhelms existing approaches in two respects. Firstly, AMOD outperforms existing web attack detection methods with an F-value of 99.50%and FP rate of 0.001%. Secondly, the total number of malicious queries obtained by SVM HYBRID is3.07 times that by the popular support vector machine adaptive learning(SVM AL) method. The malicious queries obtained can be used to update the web application firewall(WAF) signature library. 关 键 词:攻击检测 询问 系统 应用程序 学习策略 参数传递 敏感数据 机器制造
相关文献

参考文献(53)

引证文献(1)

耦合文献(4)

网站首页 | 关于我们 | 联系我们 | 产品服务 | 客服中心 | 广告服务 | 版权声明 | 网站联盟 | 友情链接 | 售卡网点

版权所有© 渝B2-20050021-1 渝公网安备 50019002500403号 违法和不良信息举报中心

互联网出版许可证 新出网证(渝)字10号 全国400电话 - 免长途话费