作者: Mikhail Zolotukhin , Timo Hämäläinen
DOI: 10.1007/978-3-642-40316-3_33
关键词:
摘要: Nowadays HTTP servers and applications are some of the most popular targets for network attacks. In this research, we consider an algorithm intrusions detection based on simple clustering algorithms advanced processing requests which allows analysis all queries at once does not separate them by resource. The method proposed in case continuously updated web-applications require a set free attacks to build normal user behaviour model. is tested using logs acquired from large real-life web service and, as result, these detected, while number false alarms remains zero.