Anomaly Behavior Detection for the Web Application Based on LSTM
Hongxin Ma, Chunbo Wang, Hui Ying Qi · 2021 IEEE Conference on Telecommunications, Optics and Computer Science (TOCS) · 2021
With the development of the Internet, more and more services are provided through various web applications. At the same time, the number of malicious behaviors of illegal access to the web application is also growing, which seriously threatens the security of the web application itself and user data. Anomaly detection is one of the primary methods to secure the web application and user data. Most of the traditional methods use statistical or machine learning algorithms to distinguish normal users and attackers according to the self-defined features. In this paper, we present an LSTM-based web application anomaly behavior detection method, which uses more comprehensive and raw web log data. First, the original request record is converted into an 8-dimension request vector and multiple requests of the same user are connected in chrono-logical order to form a user session vector. All session vectors are used as the input of LSTM. Then, LSTM network learns the behavior patterns hidden in the session vectors by itself, extracts behavior features and performs anomaly detection. Finally, we evaluate the proposed method on a real dataset. Experimental results show that our method can distinguish anomaly behavior well and outperforms the methods that use self-defined features, including K-means, PCA, KNN, NB and SVM.