english Icono del idioma   español Icono del idioma  

Por favor, use este identificador para citar o enlazar este ítem: https://hdl.handle.net/20.500.12008/29282 Cómo citar
Título: Web application attacks detection using machine learning techniques
Autor: Betarte, Gustavo
Martínez, Rodrigo
Pardo, Alvaro
Tipo: Preprint
Palabras clave: Web Application Firewall, Web Application Security, Machine Learning, Pattern Recognition
Fecha de publicación: 2018
Resumen: Web applications are permanently being exposed to attacks that exploit their vulnerabilities. In this work we investigate the use of machine learning techniques to leverage the performance of Web Application Firewalls (WAFs), systems that are used to detect and prevent attacks. We propose a characterization of the problem by defining different scenarios depending if we have valid and/or attack data available for training. We also propose two solutions: first a multi-class approach for the scenario when valid and attack data is available; and second a one-class solution when only valid data is at hand. We present results using both approaches that outperform MODSECURITY configured with the OWASP Core Rule Set out of the box, which is the baseline configuration setting of a widely deployed WAF technology.We also propose a tagged dataset based on the DRUPAL content management framework.
Descripción: 2018 17th IEEE International Conference on Machine Learning and Applications (ICMLA), 2018, pp. 1065-1072.
Editorial: IEEE
Citación: Betarte, G., Martínez, R. y Pardo, A. Web application attacks detection using machine learning techniques [Preprint] Publicado en : 17th IEEE International Conference on Machine Learning and Applications (ICMLA), 2018, pp. 1065-1072, doi: 10.1109/ICMLA.2018.00174.
Licencia: Licencia Creative Commons Atribución - No Comercial - Sin Derivadas (CC - By-NC-ND 4.0)
Aparece en las colecciones: Reportes Técnicos - Instituto de Computación

Ficheros en este ítem:
Fichero Descripción Tamaño Formato   
BMP18.pdfPreprint262,12 kBAdobe PDFVisualizar/Abrir


Este ítem está sujeto a una licencia Creative Commons Licencia Creative Commons Creative Commons