A Dynamic Anomaly Detection Model for Web User Behavior Based on HsMM

Yi Xie,Shun-Zheng Yu
DOI: https://doi.org/10.1109/cscwd.2006.253054
2006-01-01
Abstract:It is difficult for the existing anomaly detection methods to distinguish the burst of normal traffic from the anomalous traffic in a large-scale Web site. This paper uses hidden semi-Markov model to describe the browsing behaviors of Web users. An efficient recursive algorithm for this model is presented for the online implementation of model update, which is used to track the Web users' browsing behaviors dynamically. An anomaly detection scheme is proposed for the application of this model. Likelihood of an observation sequence on a user browsing behaviors fitting to the model is used as a measure of normality of the user. Finally, an experiment is conducted to validate our model and algorithms, which is based on a real traffic data and an emulated distributed denial of service attack
What problem does this paper attempt to address?