A modular architecture for the analysis of HTTP payloads based on multiple classifiers

  • Authors:
  • Davide Ariu;Giorgio Giacinto

  • Affiliations:
  • Department of Electrical and Electronic Engineering, University of Cagliari, Italy;Department of Electrical and Electronic Engineering, University of Cagliari, Italy

  • Venue:
  • MCS'11 Proceedings of the 10th international conference on Multiple classifier systems
  • Year:
  • 2011

Quantified Score

Hi-index 0.00

Visualization

Abstract

In this paper we propose an Intrusion Detection System (IDS) for the detection of attacks against a web server. The system analyzes the requests received by a web server, and is based on a two-stages classification algorithm that heavily relies on the MCS paradigm. In the first stage the structure of the HTTP requests is modeled using several ensembles of Hidden Markov Models. Then, the outputs of these ensembles are combined using a one-class classification algorithm.We evaluated the system on several datasets of real traffic and real attacks. Experimental results, and comparisons with state-of.the.art detection systems show the effectiveness of the proposed approach.