Web Application Anomaly Detection Based On Converting HTTP Request Parameters To Numeric

Huynh Hoang Tan, Trần Văn Hoài · 2021

Nowadays, the fast growth of cloud computing, IoT, and intelligent terminal leads to a shift from traditional software to web-based applications. Consequently, they are subject to being attacked by computer cybercriminals. In particular, a query string sent to web applications contains information about resources on the server, which are vulnerable to be exploited for an attack. To protect web applications, organizations usually deploy a web application firewall (WAF) to monitor, warn and prevent attacks based on known attack patterns or anomaly detections. In this paper, we propose a method that converts an HTTP query string to a number. In other words, this technique will transform the problem of detecting “anomalous queries” into “anomalous univariate data points.” Then, the proposed method clusters the numeric data points by the mean shift clustering algorithm in an unsupervised manner. Experimental results show that our anomaly detection gets high accuracy in many web applications, even with confusing authentication web applications (FPR=11%, ACC=80%). Without data labeling, the proposed method can shatter queries into groups for further classification, and therefore, is quite applicable in actual WAF products.

Read the paper · More papers on PaperTik