Big data analysis for detection of web brute-force attack

Wenjin ZHANG, Zhongyu QIN, Zhao FENG, Jiaqi Liu, Wei Liu, Xinan Tang · JOURNAL OF SHENZHEN UNIVERSITY SCIENCE AND ENGINEERING · 2020

Brute force cracking attacks are one of the main means of intruding into the network to cause data leakage. With the increasing popularity of the internet, their degree of harm is increasing. The campus network is a relatively open area in the entire internet, and the information of students, faculty and staff is even more scrutinized by hackers. At the same time, the internal business system of the campus network is intricate, making it difficult to manage the account and password of students, faculty, and staff, leaving a huge operating space for hackers to perform brute force cracking attacks. This paper proposes a detection algorithm against web brute force cracking attacks by obtaining and analyzing hypertext transfer protocol (HTTP) metadata based on full traffic. The metadata of the network protocol is obtained by collecting the full network traffic by the bypass TAP, and is further cleaned up and sent to the big data platform for storage and analysis. The experiment shows that the proposed algorithm can grasp the security status of the entire campus network in real time.

Read the paper · More papers on PaperTik