Implementation of IDS for web application attack using evolutionary algorithm
Saba Khan, Dilip Motwani · 2017
Web application security is a threat to the world's information technology infrastructure. The most widely used accepted solution to this threat is to deploy an Intrusion Detection System(IDS). Such systems currently rely on either signature of the attack or changes in the behavior patterns of the system to identify an intruder. These systems, either signature-based or anomaly-based, are readily understood by attackers. Problem occurs when attacks are not detected by the existing IDS because the attack does not fit the pre-defined attack signatures. This work intends to address this problem. In this paper, we implemented two IDS model which includes an anomaly detection technique measured by cross entropy and a signature-based attack detection using genetic algorithm. Both the methods, that is signature based as well as anomaly based IDS are used to detect even more attacks than either approach could detect alone. By compiling each of the approaches, additional false positive and false negative attacks can be discovered as well. Those included in this work are SQL injection, cross-site scripting and remote file inclusion.