Comparing Anomaly Detection Techniques for HTTP
Source: Carleton University
Much data access occurs via HTTP, which is becoming a universal transport protocol. Because of this, it has become a common exploit target and several HTTP specific IDSs have been proposed as a response. However, each IDS is developed and tested independently, and direct comparisons are difficult. The authors describe a framework for testing IDS algorithms, and apply it to several proposed anomaly detection algorithms, testing using identical data and test environment. The results show serious limitations in all approaches, and they make predictions about requirements for successful anomaly detection approaches used to protect web servers.
| Format: | Size: | 266.80 | |
| Date: | Jun 2007 |
People who downloaded this item also downloaded
- 10 Tech Skills That Are Heading the Way of the Dinosaur - 2012
- White paper: Why performance management? A guide for the midsize organization



