A modular architecture for the analysis of HTTP payloads based on Multiple Classifiers

TitleA modular architecture for the analysis of HTTP payloads based on Multiple Classifiers
Publication TypeConference Paper
Year of Publication2011
AuthorsAriu, D, Giacinto, G
EditorSansone, C, Kittler, J, Roli, F
Conference Name10th Int. Workshop on Multiple Classifier Systems (MCS 2011), Naples, Italy
Date Published15/06/2011
Keywordsids00, mcs00
Abstract
In this paper we propose an Intrusion Detection System (IDS) for the detection of attacks against a web server. The system analyzes the requests received by a web server, and is based on a two-stages classification algorithm that heavily relies on the MCS paradigm. In the first stage the structure of the HTTP requests is modeled using several ensembles of Hidden Markov Models. Then, the outputs of these ensembles are combined using a one-class classification algorithm. We evaluated the system on several datasets of real traffic and real attacks. Experimental results, and comparisons with state-of.the.art detection systems show the effectiveness of the proposed approach.
Notes
Citation Key 1092
Download: 
AttachmentSize
Ariu_MCS2011.pdf244.9 KB