Pattern Recognition Approach for Anomaly Detection of Web-based Attacks

Aruna Jamdagni, Zhiyuan Tan, Ren Ping Liu, Priyadarsi Nanda, Xiangjian He · UTS ePRESS (University of Technology Sydney) · 2010

The universal use of the Internet has made it more difficult to achieve high security. Attackers target web applications instead of Telnet ports. Cyber-attacks and breaches of information security are increasing in frequency. The goal of Intrusion Detection Systems (IDSs) is to monitor network traffic and detect web-based attacks. Common IDSs are either signature based or anomaly based. Signature based IDS is unable to detect novel attack (Le., zero-day) or polymorphic attacks, until the signature database is updated. On the other hand, an anomaly-based IDS can detect new attacks and polymorphic attacks. However, anomaly based system has a relatively high number of false positives.

Read the paper · More papers on PaperTik