Poster abstract: Streamlined anomaly detection in web requests using recurrent neural networks
Arne Bochem, Hang Zhang, Dieter Hogrefe · 2017
Web applications commonly provide a high attack surface. In today's world of high impact attacks, protecting them against both known and unknown attacks becomes more important than ever. We present an approach of machine learning based anomaly detection to flexibly detect anomalous requests. Our approach leverages long short-term memory (LSTM) neural networks to learn a detailed model of normal requests without requiring domain knowledge. Detection performance is flexible and can be adjusted depending on the requirements of a given use case. We evaluate our approach using the CSIC 2010 dataset of HTTP requests containing various types of attacks. After training on strictly normal, basically unprocessed data, we can successfully detect anomalous requests containing various types of attacks with high probability.