The rapid growth of web applications and services has raised cybersecurity concerns, particularly in terms of detecting and preventing malicious web session attacks. These attacks cause significant dangers to users, including potential data breaches, illegal access, and a variety of other criminal behaviors. To tackle this challenge, this paper introduces an innovative methodology designed to detect malicious web sessions by harnessing the power of a machine learning-driven classifier. Central to this approach is the fusion of an embedding layer with machine learning techniques, aimed at comprehensively scrutinizing the intricate features inherent in web sessions. The validation of this technique draws upon a diverse range of datasets, comprising a unique compilation of Internet banking web request logs from Yap Kredi Teknoloji, alongside established datasets like CSIC 2010, WAF, and HTTP Params. Additionally, this study utilizes well-known methodologies including Convolutional Neural Networks, Support Vector Machines, and ensemble-based methods (Random Forest, Gradient Boosting Classifier, AdaBoost Classifier, and Extra Tree Classifier), and the study underscores the superior efficacy of the proposed technique. Notably, the adoption of Random Forest as the classifier yields a remarkable accuracy rate of 99.17%, outperforming traditional approaches. These findings underscore the significant potential of the proposed technique in efficiently identifying and thwarting malicious web sessions, thereby fortifying the security posture of web environments.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Malicious Web Session Detection with Ensemble-Based Methods

  • Dilek Yılmazer Demirel,
  • Mehmet Tahir Sandıkkaya

摘要

The rapid growth of web applications and services has raised cybersecurity concerns, particularly in terms of detecting and preventing malicious web session attacks. These attacks cause significant dangers to users, including potential data breaches, illegal access, and a variety of other criminal behaviors. To tackle this challenge, this paper introduces an innovative methodology designed to detect malicious web sessions by harnessing the power of a machine learning-driven classifier. Central to this approach is the fusion of an embedding layer with machine learning techniques, aimed at comprehensively scrutinizing the intricate features inherent in web sessions. The validation of this technique draws upon a diverse range of datasets, comprising a unique compilation of Internet banking web request logs from Yap Kredi Teknoloji, alongside established datasets like CSIC 2010, WAF, and HTTP Params. Additionally, this study utilizes well-known methodologies including Convolutional Neural Networks, Support Vector Machines, and ensemble-based methods (Random Forest, Gradient Boosting Classifier, AdaBoost Classifier, and Extra Tree Classifier), and the study underscores the superior efficacy of the proposed technique. Notably, the adoption of Random Forest as the classifier yields a remarkable accuracy rate of 99.17%, outperforming traditional approaches. These findings underscore the significant potential of the proposed technique in efficiently identifying and thwarting malicious web sessions, thereby fortifying the security posture of web environments.