arXiv:2505.17077cs.CRcs.LG2025-05

用增量特征选择提升HTTP洪水攻击实时检测效率

Streamlining HTTP Flooding Attack Detection through Incremental Feature Selection

  • 基于互信息与相关性构建增量特征筛选方法
  • 在近实时条件下实现最佳分类性能
  • 适合需要高效网络入侵检测的系统开发者

Web应用主要依赖HTTP协议在系统间传输网页。尽管存在多种应用层协议,但HTTP因通用性强且易于集成而成为攻击者首选目标,因其默认不被检测系统拦截。攻击者利用此特性发起针对Web应用的攻击。本文提出一种检测此类攻击的方法,核心是基于互信息与相关性的增量特征子集选择(INFS-MICC)方法,可识别高度相关且独立的特征子集,从而在近实时条件下实现最优分类性能,有效检测HTTP洪水攻击。

原文摘要 · Abstract (English)

Applications over the Web primarily rely on the HTTP protocol to transmit web pages to and from systems. There are a variety of application layer protocols, but among all, HTTP is the most targeted because of its versatility and ease of integration with online services. The attackers leverage the fact that by default no detection system blocks any HTTP traffic. Thus, by exploiting such characteristics of the protocol, attacks are launched against web applications. HTTP flooding attacks are one such attack in the application layer of the OSI model. In this paper, a method for the detection of such an attack is proposed. The heart of the detection method is an incremental feature subset selection method based on mutual information and correlation. INFS-MICC helps in identifying a subset of highly relevant and independent feature subset so as to detect HTTP Flooding attacks with best possible classification performance in near-real time.

入侵检测特征选择网络安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。