Yayın:
Web Application Firewall Based on Anomaly Detection using Deep Learning

dc.contributor.authorToprak, Sezer
dc.contributor.authorYavuz, Ali Gokhan
dc.date.accessioned2026-06-27T14:45:18Z
dc.date.issued2022
dc.description.abstractAnomaly detection has been researched in different areas and application domains. The main difficulty is to identify the outliers from the normals in case of encountering an input that has unique features and new values. In order to accomplish this task, the research focusses on using Machine Learning and Deep Learning techniques. In the world of the Internet, we are facing a similar problem to identify whether a website request contains malicious activity or just a normal request. Web Application Firewall (WAF) systems provide such protection against malicious requests using a rule based approach. In recent years, anomaly based solutions have been integrated in addition to rule based systems. Still, such solutions can only provide security up to a point and such techniques can generate false-positive results that leave the backend systems vulnerable and most of the time rules based protection can be bypassed with simple tricks (eg. encoding, obfuscation). The main focus of the research is WAF systems that employ single and stacked LSTM layers which are based on character sequences of user supplied data and revealing hyper-parameter values for optimal results. A semi-supervised approach is used and trained with PayloadAllTheThings dataset containing real attack payloads and only normal payloads of HTTP Dataset CSIC 2010 are used. The success rate of the technique - whether the user input is identified as malicious or normal - is measured using F1 scores. The proposed model demonstrated high F1 scores and success in terms of detection and classification of the attacks.en
dc.description.urihttps://doi.org/10.26650/acin.1039042
dc.identifier.doi10.26650/acin.1039042
dc.identifier.eissn2602-3563
dc.identifier.endpage244
dc.identifier.issue2
dc.identifier.startpage219
dc.identifier.urihttps://hdl.handle.net/20.500.14981/64353
dc.identifier.volume6
dc.identifier.wos001318213500007
dc.language.isoeng
dc.publisherISTANBUL UNIV
dc.relation.ispartofACTA INFOLOGICA
dc.rightsopenAccess
dc.subjectDeep learning
dc.subjectLSTM
dc.subjectweb application firewall
dc.subjectmachine learning
dc.subjectneural networks
dc.subjectweb attacks
dc.subjectanomaly detection
dc.subjectHTTP protocol
dc.subjectNOVELTY DETECTION
dc.subjectNEURAL-NETWORKS
dc.subjectComputer Science
dc.titleWeb Application Firewall Based on Anomaly Detection using Deep Learning
dc.typeArticle
dspace.entity.typePublication
local.import.sourceWOS

Dosyalar

Koleksiyonlar