LIFH: Learning Interactive Features from HTTP Payload using Image Reconstruction
Jinbu Geng, Shuhao Li, Yongzheng Zhang, Zhicheng Liu, Zhenyu Cheng · 2021
The complexity and intelligence of the attacks towards the application layer have raised to an unprecedented level. HyperText Transfer Protocol (HTTP), as the widely used application layer protocol, is part of the main vectors for various malicious attacks. The previous detection based on Deep Packet Inspection (DPI) relies heavily on packets, which leads to insufficient detection and a high false alarm rate. In this paper, we propose LIFH, a deep neural network model equipped with interactive information for detecting application-layer attacks. Firstly, the image reconstruction method is designed to reconstruct the HTTP traffic session into an image. Then, the latent features, instead of explicit features which are typically used in machine learning models, are extracted by HTTP-CNN in order to respond against forgery attacks. Finally, the high-level features are further fed to multi-classifiers to identify the traffic involved in malicious activities. We make exclusive experiments and evaluate the performance of LIFH on the standard dataset CICIDS_2017 and IIE_data collected from critical web servers. The results demonstrate that the proposed model can significantly improve the performance of malicious traffic detection with an accuracy of 99.07% and a false positive rate of 0.40% which is superior to the state of the arts.