Classification Model of Web Application Attacks

A web application is one of the most critical cyber-attack targets. One of the most common methods to detect or predict web application attacks is the classification based on HTTP requests. Glastopf is a web application honeypot that logs HTTP requests and only detects SQLi, RFI, and LFI attacks. This paper aims at increasing the number of web application attacks predicted from a Glastopf log. We design a classification model using Random Forest classifiers with the ECML/PKDD 2007 Discovery Challenge and HTTP CSIC 2012 Torpeda datasets to detect eight types of web application attacks, including XSS, SQLi, path traversal, LDAPi, XPath, OS Command, SSI, and CRLFi. Empirical results using two datasets show that our model has accuracy with 97,9% on average. Furthermore, using an actual Glastopf log from our VPS, the result shows that our model can enhance the prediction on Glastopf, not only limited to three types of attacks.

Paper

Full text

PDF

Classification Model of Web Application Attacks

Semantic Scholar · Computer Science · 2021

Abstract

A web application is one of the most critical cyber-attack targets. One of the most common methods to detect or predict web application attacks is the classification based on HTTP requests. Glastopf is a web application honeypot that logs HTTP requests and only detects SQLi, RFI, and LFI attacks. This paper aims at increasing the number of web application attacks predicted from a Glastopf log. We design a classification model using Random Forest classifiers with the ECML/PKDD 2007 Discovery Challenge and HTTP CSIC 2012 Torpeda datasets to detect eight types of web application attacks, including XSS, SQLi, path traversal, LDAPi, XPath, OS Command, SSI, and CRLFi. Empirical results using two datasets show that our model has accuracy with 97,9% on average. Furthermore, using an actual Glastopf log from our VPS, the result shows that our model can enhance the prediction on Glastopf, not only limited to three types of attacks.

Similar papers

© 2026 NYSGPT2525 LLC