Light-weight detection of HTTP attacks for large-scale Web sites

Yi Xie,Shun-zheng Yu
DOI: https://doi.org/10.1109/ICCS.2008.4737369
2008-01-01
Abstract:This paper is focused on a new type sneaky HTTP attack which has no obvious anomaly characteristics. A new light-weight anomaly detection scheme is introduced for large-scale Web sites whose workload is much heavier and more bursty than the general Web sites. Based on stack distance values of HTTP requests, an improved event-driven hidden semi-Markov model is applied to describe the stochastic process of HTTP traffic. Normalized Viterbi score of incoming HTTP request sequence fitting to the given model is used as a measure criterion. Experiments based on a real Web traffic and an emulated attack are implemented to valid the proposal.
What problem does this paper attempt to address?