Cross-Domain Collaborative Anomaly Detection: So Far Yet So Close
نویسندگان
چکیده
Web applications have emerged as the primary means of access to vital and sensitive services such as online payment systems and databases storing personally identifiable information. Unfortunately, the need for ubiquitous and often anonymous access exposes web servers to adversaries. Indeed, network-borne zero-day attacks pose a critical and widespread threat to web servers that cannot be mitigated by the use of signature-based intrusion detection systems. To detect previously unseen attacks, we correlate web requests containing user submitted content across multiple web servers that is deemed abnormal by local Content Anomaly Detection (CAD) sensors. The cross-site information exchange happens in real-time leveraging privacy preserving data structures. We filter out high entropy and rarely seen legitimate requests reducing the amount of data and time an operator has to spend sifting through alerts. Our results come from a fully working prototype using eleven weeks of real-world data from production web servers. During that period, we identify at least three application-specific attacks not belonging to an existing class of web attacks as well as a wide-range of traditional classes of attacks including SQL injection, directory traversal, and code inclusion without using human specified knowledge or input.
منابع مشابه
Close Yet Distinctive Domain Adaptation
Domain adaptation is transfer learning which aims to generalize a learning model across training and testing data with different distributions. Most previous research tackle this problem in seeking a shared feature representation between source and target domains while reducing the mismatch of their data distributions. In this paper, we propose a close yet discriminative domain adaptation metho...
متن کاملPossible Evidence of Disoriented Chiral Condensates from the Anomaly in Ω and Ω̄ Abundances at the SPS
No conventional picture of nucleus-nucleus collisions has yet been able to explain the abundance of Ω and Ω̄ in central collisions between Pb nuclei at 158 A GeV at the CERN SPS. We argue that such a deviation from predictions of statistical thermal models and numerical simulations is evidence that they are produced as topological defects in the form of skyrmions arising from the formation of di...
متن کاملRMS: a platform for managing cross-disciplinary and multi-institutional research project collaboration
BACKGROUND Cross-institutional cross-disciplinary collaboration has become a trend as researchers move toward building more productive and innovative teams for scientific research. Research collaboration is significantly changing the organizational structure and strategies used in the clinical and translational science domain. However, due to the obstacles of diverse administrative structures, ...
متن کاملInterpretive Modeling of Simple-as- Possible-plasma Discharges on Diii–d Using the Oedge Code
Recently a number of major, unanticipated effects have been reported in tokamak edge research raising the question of whether we understand the controlling physics of the edge. This report is on the first part – here focused on the outer divertor – of a systematic study of the simplest possible edge plasma – no ELMs, no detachment, etc. – for a set of 10 repeat, highlydiagnosed, single-null, di...
متن کاملSome comments on Super-Kamiokande’s multi-ring analysis
The super-Kamiokande collaboration have used multi-ring events to discriminate between the ν µ → ν τ and ν µ → ν s solutions to the atmospheric neutrino anomaly. We show that the effect of systematic uncertainties in cross sections are so significant that the usefulness of multi-ring data to distinguish between these two solutions is doubtful.
متن کامل