Visualizing Intrusions: Watching the Webserver

Kluwer Academic Publishers eBooks · 2006

In summary, the hypothesis that the combination of anomaly based log reduction and visualization would provide us with the benefits of both approaches while counteracting the drawbacks was supported. Furthermore the anomaly based log reduction system could indeed be very simple and still successfully serve as a front end to the visualization system. The hypothesis that visualizing the structure of the requests strings themselves cut into components would enable the operator to discard benign accesses with relative ease was supported. There was less evidence for the corresponding hypothesis: that one could just as easily identify malicious patterns. A few meta classes of attacks did exhibit features that set them apart from the benign traffic, but others did not to a significant degree. The presented method is relatively time efficient, and the operator learns about the usage of the website. Notably unusual but benign (often dynamic) traffic that is more varied and hence more prone to misclassification is studied in more detail. The work invested in parring down the graph can be amortized over subsequent investigations, where the webserver logs for the following months contain less and less new traffic, and hence can be visualized more quickly, especially if one remembers what accesses were seen previously and why it was decided to discard them as uninteresting.

Read the paper · More papers on PaperTik