Web Services Analysis and Threat Detection Through Score-Based Anomaly Detection System and Data Visualizations

Jesús A. Rodríguez Rivera, José Ortiz-Ubarri · 2024

Network services are in a constant threat of cyber-attacks and system administrators need efficient ways to detect them. However, access to cybersecurity, as well as skills, are limited in the current landscape. Cybersecurity technology could help mitigate these issues for many and tools focusing on web threat detection and automatization could be a first step in dealing with this issue. The goal of our project is to research the combination of data visualizations and automated anomaly detection methods to reduce false alarms and aid entities with a need to expand the defenses of their own systems. Our methods of anomaly detection combine signature-based and anomaly-based detection to monitor suspicious activity captured in web access logs. For our research, a web access log analysis tool was developed, which provides a visual summary of important information from log files. The tool also provides automated anomaly detection which highlights points on graphs that represent potential security threats. A score system was implemented to distinguish anomalies based on their level of malicious behavior. Users can perform in-depth analysis of their access logs by accessing file data through their graphs. Our tool was successful at detecting network attacks such as vulnerability scans, and injection attempts in the visualizations and highlighted alerts.

Read the paper · More papers on PaperTik