月旦知識庫
 
  1. 熱門:
 
首頁 臺灣期刊   法律   公行政治   醫事相關   財經   社會學   教育   其他 大陸期刊   核心   重要期刊 DOI文章
理工研究國際期刊 本站僅提供期刊文獻檢索。
  【月旦知識庫】是否收錄該篇全文,敬請【登入】查詢為準。
最新【購點活動】


篇名
An Efficient Web Log Filter Scheme for Web Abnormal Behaviors
作者 Henry Chin-yang Tseng (Henry Chin-yang Tseng)Shin-Yun Chang (Shin-Yun Chang)Tong-Ying Juang (Tong-Ying Juang)
中文摘要
隨著科技的快速發展,網路相關服務愈發複雜與趨向多變化。為了更好地保護這些網路服務的安全與隱私,主動進行異常檢查與分析的動作就變得相當重要。故,因應日常安全檢查為事後主動追蹤的需求,我們提出一種針對Web異常行為的Web Log篩選機制,結合挖掘已知攻擊行為與未知異常行為兩種層面的資料,並藉這些資料之互補性,達成較快且不失過多準確度的目的。此機制首先利用PHPIDS的特徵規則進行正則表示式比對,再進行資料預處理挑出可疑的Log及轉化HTTP請求欄位形成特徵矩陣,使用隨機投影進行降階,並利用馬氏距離找出異常者且為其計算異常分數。若找出的該筆Log 太過相異將被標記為異常者,直至全數Log檢測完為止。為了有更切合的結果,此機制利用了現實公司的真實資料測試,並實驗出適切之參數。除此之外,此機制尚有簡單容易實現、快速且不失過多準確度、無需清理訓練資料的優點。
英文摘要
With the rapid development of technology, network services are becoming more complex and changeful. To protect the security and privacy of these network services, check and analyze abnormal behaviors actively becomes very important. In order to meet the need of check and analyze abnormal behaviors actively for routine security check, we try to find the data of known attacks and anomaly behaviors, propose a web log filter scheme for web abnormal behaviors which aims to quickly anomaly detection and also provides accuracy. The scheme uses the signature rules of PHPIDS to match, preprocesses network logs to find suspicious logs and form a feature matrix, reduces the dimensionality of matrix using random projection, uses Mahalanobis distance to identify outliers and calculate an anomaly score of the outliers. If the log line is too different, we flag it anomaly, until all of the logs are checked. In order to get the better outcome, we use the data of real-world company to test the scheme and find the suitable parameter. In addition, the advantage of the scheme is simple to implement easily, fast and without losing too much accuracy and does not need to clean training data.
起訖頁 25-31
關鍵詞 Web Log分析Web Log篩選Web Log AnalysisWeb Log FilterWeb Log
刊名 理工研究國際期刊  
期數 201412 (4:4期)
出版單位 國立臺南大學
該期刊-上一篇 Image ENCRYPTION on HDR IMAGES for OpenEXR Format
該期刊-下一篇 Using Stationary Relay Nodes (Thrown Boxes) to Maximize Message Forwarding Performance in Delay-Tolerant Networks
 

新書閱讀



最新影音


優惠活動




讀者服務專線:+886-2-23756688 傳真:+886-2-23318496
地址:臺北市館前路28 號 7 樓 客服信箱
Copyright © 元照出版 All rights reserved. 版權所有,禁止轉貼節錄