Research on Network Attack Monitoring Based on Application HTTP Traffic Parameter Analysis
Yizhen Sun, Peng Zhou, Junchi Peng, Dawei Dai, Yuxi Wu, Jingchuan Feng · 2025
Currently, enterprise web application security monitoring predominantly relies on devices such as Web Application Firewalls (WAF) and Intrusion Prevention Systems (IPS). However, these tools often struggle to detect targeted penetration and business logic attacks. This paper introduces a novel security monitoring technology that analyzes session parameter characteristics of web applications. By extracting access parameters, our method establishes six key features: parameter name, fixed-class parameter value, parameter value length, parameter value type, parameter request frequency within a single session, and user-binding class parameter value. A baseline model is then created through feature learning of normal sessions, allowing for effective identification of penetration attacks that deviate from typical session patterns. Testing on real enterprise web application session logs demonstrates that this method achieves a false alarm rate of 0.18% and an accuracy of 99.77%. It effectively monitors penetration attacks that traditional security devices often miss, thereby compensating for their limitations and offering significant practical application value.