A Machine Learning-based Malicious Payload Detection and Classification Framework for New Web Attacks

Shahin Ramezany, Rachsuda Setthawong, Thitipong Tanprasert · 2022 19th International Conference on Electrical Engineering/Electronics, Computer, Telecommunications and Information Technology (ECTI-CON) · 2022

In the modern world, cyber-crimes are arguably the biggest threat to companies. Web attacks are one of the most significant chunks of cyber security threats. COVID-19 remote working also makes cyber threats even a bigger problem. This paper proposes a customized machine learning-based framework to capture and classify web attacks. We release a new data set with many new entities and modern variants. the proposed open-source framework, illustrating how to generate a comprehensive dataset and extract payloads from HTTP requests. Next, we do feature engineering, term weighting, maxing out features, n-gram based character level extraction, and add commonly misclassified payloads. Finally, the experiments are set using three promising classification functions: support vector machine (SVM), random forest (RF), and stochastic gradient descent (SGD) on our dataset and compared the classification results; overall, SVM outperforms other algorithms classifying almost web attack's types in terms of accuracy.

Read the paper · More papers on PaperTik