Protecting the application layer in the public domain with machine learning methods
Rafał Kozik, Michał Choraś · Logic Journal of IGPL · 2018
Currently, we can observe that vulnerable web pages are a common element in many high-profile cyberattacks. On the other hand, web applications (as well as web services) have become an inherent element of many supply chains. In order to protect the web services against some of the cyberattacks, one can adapt web application firewalls (WAF) solutions. However, quite often a challenge for typical WAF software is the fact that HTTP can be used as transport by other protocols or as a mix of other various encoding techniques. Therefore, in this paper, we propose a flexible schema for automated application layer request structure identification. Our experiments show that this technique allows us to further improve the effectiveness of known detection methods used in this research domain. In this paper, we show the possible practical application of the proposed cybersecurity solution in the public domain, namely public administration web-based systems and healthcare sectors. From the scientific point of view, we presented the results of various classifiers and pattern extraction techniques. We have also addressed the possible deployment of the proposed solution in Big Data-enabled environments.