Anomaly detection for web server based on smooth support vector machine.
Saved in:
| Title: | Anomaly detection for web server based on smooth support vector machine. |
|---|---|
| Authors: | Shi-Jinn Horng1,2 horngsj@yahoo.com.tw, Pingzhi Fan3 p.fan@ieee.org, Ming-Yang Su4 minysu@mcu.edu.tw, Yuan-Hsin Chen2 yschen@nuu.edu.tw, Cheng-Ling Lee5 cherry@nuu.edu.tw, Shao-Wei Lan1 x_sk2@yahoo.com.tw |
| Source: | Computer Systems Science & Engineering. May2008, Vol. 23 Issue 3, p209-218. 10p. 3 Diagrams, 4 Charts, 1 Graph. |
| Subjects: | Web server software, Computer network security, False alarms, Microsoft software, Client/server computing, Computer security |
| Abstract: | A network-based intrusion detection system (NIDS) for detecting attacks on Microsoft IIS web server was proposed. The classifier used in the system is based on smooth support vector machine (SSVM). SSVM is a variation of support vector machine (SVM) with higher detection rate and shorter training lime. Since SSVM is a binary classifier, for the sake of recognizing different attacks, we constructed hierarchical SSVMs to do it. The NIDS captures HTTP request packet, and derives features from payload but header information. By experiments, the NIDS captured 55,308 HTTP request packets on-line, consisting of 31,034 normal and 24,274 abnormal packets, the true positive rate is 99.40% and the false alarm is 6.85%. The proposed NID has another merit; that is, it has the ability to detect unknown or even novel attacks, ranging from 65.13% to 97.33%, depending on different signatures missed in training phase. Moreover, our NIDS takes only 7.2 x 10-4 second in average for processing an incoming packet in a PC with 2.4GHZ CPU and 256MB RAM. The high accuracy and speed make our NIDS more practicable in the real world. [ABSTRACT FROM AUTHOR] |
| Copyright of Computer Systems Science & Engineering is the property of Tech Science Press and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.) | |
| Database: | Engineering Source |
| FullText | Text: Availability: 0 |
|---|---|
| Header | DbId: egs DbLabel: Engineering Source An: 34113543 AccessLevel: 6 PubType: Academic Journal PubTypeId: academicJournal PreciseRelevancyScore: 0 |
| IllustrationInfo | |
| Items | – Name: Title Label: Title Group: Ti Data: Anomaly detection for web server based on smooth support vector machine. – Name: Author Label: Authors Group: Au Data: <searchLink fieldCode="AR" term="%22Shi-Jinn+Horng%22">Shi-Jinn Horng</searchLink><relatesTo>1,2</relatesTo><i> horngsj@yahoo.com.tw</i><br /><searchLink fieldCode="AR" term="%22Pingzhi+Fan%22">Pingzhi Fan</searchLink><relatesTo>3</relatesTo><i> p.fan@ieee.org</i><br /><searchLink fieldCode="AR" term="%22Ming-Yang+Su%22">Ming-Yang Su</searchLink><relatesTo>4</relatesTo><i> minysu@mcu.edu.tw</i><br /><searchLink fieldCode="AR" term="%22Yuan-Hsin+Chen%22">Yuan-Hsin Chen</searchLink><relatesTo>2</relatesTo><i> yschen@nuu.edu.tw</i><br /><searchLink fieldCode="AR" term="%22Cheng-Ling+Lee%22">Cheng-Ling Lee</searchLink><relatesTo>5</relatesTo><i> cherry@nuu.edu.tw</i><br /><searchLink fieldCode="AR" term="%22Shao-Wei+Lan%22">Shao-Wei Lan</searchLink><relatesTo>1</relatesTo><i> x_sk2@yahoo.com.tw</i> – Name: TitleSource Label: Source Group: Src Data: <searchLink fieldCode="JN" term="%22Computer+Systems+Science+%26+Engineering%22">Computer Systems Science & Engineering</searchLink>. May2008, Vol. 23 Issue 3, p209-218. 10p. 3 Diagrams, 4 Charts, 1 Graph. – Name: Subject Label: Subjects Group: Su Data: <searchLink fieldCode="DE" term="%22Web+server+software%22">Web server software</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+network+security%22">Computer network security</searchLink><br /><searchLink fieldCode="DE" term="%22False+alarms%22">False alarms</searchLink><br /><searchLink fieldCode="DE" term="%22Microsoft+software%22">Microsoft software</searchLink><br /><searchLink fieldCode="DE" term="%22Client%2Fserver+computing%22">Client/server computing</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+security%22">Computer security</searchLink> – Name: Abstract Label: Abstract Group: Ab Data: A network-based intrusion detection system (NIDS) for detecting attacks on Microsoft IIS web server was proposed. The classifier used in the system is based on smooth support vector machine (SSVM). SSVM is a variation of support vector machine (SVM) with higher detection rate and shorter training lime. Since SSVM is a binary classifier, for the sake of recognizing different attacks, we constructed hierarchical SSVMs to do it. The NIDS captures HTTP request packet, and derives features from payload but header information. By experiments, the NIDS captured 55,308 HTTP request packets on-line, consisting of 31,034 normal and 24,274 abnormal packets, the true positive rate is 99.40% and the false alarm is 6.85%. The proposed NID has another merit; that is, it has the ability to detect unknown or even novel attacks, ranging from 65.13% to 97.33%, depending on different signatures missed in training phase. Moreover, our NIDS takes only 7.2 x 10-4 second in average for processing an incoming packet in a PC with 2.4GHZ CPU and 256MB RAM. The high accuracy and speed make our NIDS more practicable in the real world. [ABSTRACT FROM AUTHOR] – Name: AbstractSuppliedCopyright Label: Group: Ab Data: <i>Copyright of Computer Systems Science & Engineering is the property of Tech Science Press and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.) |
| PLink | https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=egs&AN=34113543 |
| RecordInfo | BibRecord: BibEntity: Languages: – Code: eng Text: English PhysicalDescription: Pagination: PageCount: 10 StartPage: 209 Subjects: – SubjectFull: Web server software Type: general – SubjectFull: Computer network security Type: general – SubjectFull: False alarms Type: general – SubjectFull: Microsoft software Type: general – SubjectFull: Client/server computing Type: general – SubjectFull: Computer security Type: general Titles: – TitleFull: Anomaly detection for web server based on smooth support vector machine. Type: main BibRelationships: HasContributorRelationships: – PersonEntity: Name: NameFull: Shi-Jinn Horng – PersonEntity: Name: NameFull: Pingzhi Fan – PersonEntity: Name: NameFull: Ming-Yang Su – PersonEntity: Name: NameFull: Yuan-Hsin Chen – PersonEntity: Name: NameFull: Cheng-Ling Lee – PersonEntity: Name: NameFull: Shao-Wei Lan IsPartOfRelationships: – BibEntity: Dates: – D: 01 M: 05 Text: May2008 Type: published Y: 2008 Identifiers: – Type: issn-print Value: 02676192 Numbering: – Type: volume Value: 23 – Type: issue Value: 3 Titles: – TitleFull: Computer Systems Science & Engineering Type: main |
| ResultId | 1 |