Discover abnormal behaviors using HTTP header fields measurement

1Citations
Citations of this article
2Readers
Mendeley users who have this article in their library.
Get full text

Abstract

In recent years, in order to be secure, more and more Intrusion Detection Systems (IDS) and firewalls have been used to detect and block malicious applications or even unknown protocols. As a result, some malicious applications begin to shape themselves as common application protocols to get rid of detection. Being an important protocol for many Internet services, HTTP is responsible more than half of the total traffic volume. As a result, many applications choose HTTP protocol as their shaping object, leading to many abnormal behaviors. In the paper, we study the problem of discovering these abnormal behaviors in HTTP protocol. A method based on HTTP header fields’ measurement is proposed. We measure HTTP header fields’ information from HTTP traffic from normal application such as IE-8, find some characteristics and we use them to find abnormal behaviors of shaping HTTP protocol.

Cite

CITATION STYLE

APA

Bai, Q., Xiong, G., Zhao, Y., & Li, Z. (2015). Discover abnormal behaviors using HTTP header fields measurement. In Communications in Computer and Information Science (Vol. 557, pp. 89–100). Springer Verlag. https://doi.org/10.1007/978-3-662-48683-2_9

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free