KMITL

Permanent URI for this communityhttps://dspace.kmitl.ac.th/handle/123456789/1

Browse

Search Results

Now showing 1 - 3 of 3
  • Some of the metrics are blocked by your 
    Item type:Item,
    Web attack detection using chromatography-like entropy analysis
    (2015-01-01)
    Watcharapupong, Akkradach
    ;
    Threepak, Thanunchai
    Web services are mostly attacked in various ways directly and indirectly. We calculate the Shannon entropy from web server log files, especially access logs, and then estimate the entropy distance to detect intrusions and identified them by distinct attack word lists as general, cross-site script, and SQL injection attacks. The experiment shows that our proposed chromatography-like entropy analysis method can detect and identify these behaviors.
  • Some of the metrics are blocked by your 
    Item type:Item,
    Web attack detection using entropy-based analysis
    (2014-01-01)
    Threepak, T.
    ;
    Watcharapupong, A.
    Web attacks are increases both magnitude and complexity. In this paper, we try to use the Shannon entropy analysis to detect these attacks. Our approach examines web access logging text using the principle that web attacking scripts usually have more sophisticated request patterns than legitimate ones. Risk level of attacking incidents are indicated by the average (AVG) and standard deviation (SD) of each entropy period, i.e., Alpha and Beta lines which are equal to AVG-SD and AVG-2*SD, respectively. They represent boundaries in detection scheme. As the result, our technique is not only used as high accurate procedure to investigate web request anomaly behaviors, but also useful to prune huge application access log files and focus on potential intrusive events. The experiments show that our proposed process can detect anomaly requests in web application system with proper effectiveness and low false alarm rate. © 2014 IEEE.
  • Some of the metrics are blocked by your 
    Item type:Item,
    Anomaly SQL SELECT-statement detection using entropy analysis
    (2014-01-01)
    Threepak, Thanunchai
    ;
    Watcharapupong, Akkradach
    Database systems are often intruded because they store valuable information and can be accessed through Internet web applications which sometimes are not developed with security in mind. Attackers can inject some crafted inputs to those programs that work on database systems so that some unexpected results occur. We analyze the database system log files, focus on query statements (SQL SELECT statements), using the Shannon entropy to detect such anomaly attempts that would change conditional entropy significantly. Our experiment shows that the proposed anomaly detection using entropy analysis is effective. © 2014 Springer International Publishing Switzerland.