Measuring the Normality of Web Proxies' Behavior Based on Locality Principles

  • Authors:
  • Yi Xie;Shun-Zheng Yu

  • Affiliations:
  • Department of Electrical and Communication Engineering, Sun Yat-Sen University, Guangzhou, P.R. China 510275;Department of Electrical and Communication Engineering, Sun Yat-Sen University, Guangzhou, P.R. China 510275

  • Venue:
  • NPC '08 Proceedings of the IFIP International Conference on Network and Parallel Computing
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

Web Proxy and cache play important roles in the modern Internet. Although much work has been done on them, few studies were focused on the fact that these trusted intermediaries may be utilized to launch Web-based attacks and to shield the attackers' malicious behavior. This paper fills an void in this area by proposing a new server-side detection scheme based on the behavior characteristics of proxy-to-server Web traffic. Proxy's access behavior is extracted from the temporal locality and the bytes of the requested objects. A stochastic process based on Gaussian mixtures hidden semi-Markov model is applied to describe the dynamic variability of the observed variables. The entropies of those pending Web traffics launched by proxies fitting to the model are used as the criterion for attack detection. Experiments based on the real Web traffic and an emulated attack are implemented to valid the proposal.