<link rel="stylesheet" href="styles.d1f19c9cdd8054dd.css">

Automatic generation of HTTP intrusion signatures by selective identification of anomalies

dc.audiencePúblico en generales_ES
dc.coverageMéxicoes_ES
dc.date.accessioned2026-09-15T00:30:38Z
dc.date.issued2015-09-26
dc.description.abstractIn this paper, we introduce a novel methodology to automatically generate HTTP intrusion signatures for Network Intrusion Detection Systems (NIDS). Our approach relies on the use of a service-specific, semantic-aware anomaly detection scheme that combines stochastic learning with a model structure based on the protocol specification. Each incoming payload for the target service is tagged with an anomaly score obtained from probabilistically matching it against the corresponding learned model of normal usage. For those payloads whose anomaly score exceeds a given threshold, a more detailed analysis is performed to extract the portions that contribute the most to the anomaly score. Such portions are then used to build up candidate intrusion signatures, using a merging process that combines them with already existing patterns in order to keep the signature database as simple as possible by avoiding redundancies. We report results obtained with a specific implementation of our proposal for web traffic. During our evaluation, we used a well-known signature-based NIDS that sits behind the anomaly detection system and is fed with the signatures automatically generated by the latter. Our results indicate that functioning in such a way translates into an improvement of the often tedious signature generation process. Furthermore, a visual inspection of the signatures reveals that the generation procedure is quite reliable, mimicking (and, in some cases, even improving) attack patterns manually generated by security analysts.This results in an increase of the overall detection performance of the composite signature- plus anomaly-based system. (C) 2015 Elsevier Ltd. All rights reserved.es_ES
dc.identifier.doihttps://doi.org/10.1016/j.cose.2015.09.007es_ES
dc.identifier.urihttps://riuat.uat.edu.mx/handle/123456789/2603
dc.language.isoenes_ES
dc.publisherElsevier BVes_ES
dc.relationComputers & Securityes_ES
dc.relation.urlhttps://doi.org/10.1016/j.cose.2015.09.007es_ES
dc.rightsAcceso restringido / Suscripción (Metadatos de producción científica)es_ES
dc.rights.urihttp://purl.org/coar/access_right/c_16eces_ES
dc.sourceComputers & Security
dc.subjectComputer sciencees_ES
dc.subjectAnomaly-based intrusion detection systemes_ES
dc.subjectAnomaly detectiones_ES
dc.subjectIntrusion detection systemes_ES
dc.subjectSignature (topology)es_ES
dc.subjectData mininges_ES
dc.subjectAnomaly (physics)es_ES
dc.subjectPayload (computing)es_ES
dc.subjectIdentification (biology)es_ES
dc.subjectMatching (statistics)es_ES
dc.subjectProcess (computing)es_ES
dc.subjectPattern matchinges_ES
dc.subject.classificationNetwork Security and Intrusion Detectiones_ES
dc.titleAutomatic generation of HTTP intrusion signatures by selective identification of anomalieses_ES
dc.typeArtículoes_ES
uat.arbitHa sido Arbitradoes_ES
uat.autorGarcía‐Teodoro, Pedro
uat.autorDı́az-Verdejo, Jesús E.
uat.autorGarcía‐Teodoro, Pedroes_ES
uat.autorTapiador, Juan
uat.autorDı́az-Verdejo, Jesús E.es_ES
uat.autorTapiador, Juanes_ES
uat.autorSalazar-Hernandez, R.
uat.autorSalazar-Hernandez, R.es_ES
uat.institucionUniversidad Autónoma de Tamaulipas
uat.institucionUniversidad Autónoma de Tamaulipases_ES
uat.range159-174es_ES
uat.relation.urlhttps://doi.org/10.1016/j.cose.2015.09.007
uat.typeartIndexado
uat.typeartIndexadoes_ES
uat.vol55es_ES

Files