Detecting anomalous user behavior from NGINX web server logs
Lenka Benova, Ladislav Hudec · 2022
This paper proposes a method of discovering web server anomalies within NGINX logs based on user behavior. Our proposed method employing isolation forest does not require a labeled dataset and was tested on data obtained from ESET, a cybersecurity company whose enterprise network of web servers provides malware protection for its users all over the world. The goal of this paper was to efficiently detect diverse anomalies among users within large datasets containing millions of requests each day. Our method helped to further understand the behaviors of users requesting updates from chosen web servers and uncovered critical anomalies among the collected logs.