Detecting Web-Based Attacks by Machine Learning
Laicheng Cao · 2006
Web-based vulnerabilities represent a substantial portion of the security exposures of computer networks. Unfortunately, many anomaly Web-based intrusion detection systems (IDS) take on higher false alarm rate (FAR) and false negative rate (FNR). In this paper, we build this system using Adaboost, a prevailing machine learning algorithm, and its detecting model adopts a dynamic load-balancing algorithm, which can avoid packet loss and false negatives in high-performance Web severs with handling heavy traffic loads in real-time and can enhance the efficiency of detecting work. The experiments demonstrate that our system can achieve an especially low false positive rate (approximating 0.3%) and false negative rate (approaching 0.4%) while keeping an extremely low computational complexity