DeepWAF: Detecting web attacks based on CNN and LSTM models

30Citations
Citations of this article
18Readers
Mendeley users who have this article in their library.
Get full text

Abstract

The increasing popularity of web applications makes the web a main venue for attackers engaging in a myriad of cybercrimes. With large quantities of information processing and sharing by web applications, the situation for web attack detection or prevention becomes increasingly severe. We present a prototype implementation called DeepWAF to detect web attacks based on deep learning techniques. We systematically discuss the approach for effective use of the currently popular CNN and LSTM models, and their combinational models CNN-LSTM and LSTM-CNN. The experimental results on the dataset of HTTP DATASET CSIC 2010 demonstrate that our proposed four types of detection models all achieve satisfactory results, with the detection rate of approximately 95% and the false alarm rate of approximately 2%. We also carried out case studies to analyze the causes of false negatives and false positives, which can be used for further improvements. Our work further illustrates that machine learning has a promising application prospect in the field of web attack detection.

Author supplied keywords

Cite

CITATION STYLE

APA

Kuang, X., Zhang, M., Li, H., Zhao, G., Cao, H., Wu, Z., & Wang, X. (2019). DeepWAF: Detecting web attacks based on CNN and LSTM models. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 11983 LNCS, pp. 121–136). Springer. https://doi.org/10.1007/978-3-030-37352-8_11

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free