Explainable and Tamper-Resistant Real-Time Web Attack Detection System
编号:46
访问权限:仅限参会人
更新:2026-07-22 16:09:23 浏览:0次
Online
摘要
The modern web systems generate large amounts of security logs that are generally verbose, semi-structured and not readily readable during response to an incident or when exploring the legal side of an incident. Traditional Web Application Firewalls (WAFs) and Security Information and Event Management (SIEM) engines are largely preoccupied with the blocking of traffic or an aggregate in a centralized manner, yet, they do not often offer deterministic explainability and real-time cryptographic integrity verification of individual log records. To close this gap, this essay presents a lightweight, real-time, web attack detection and explainable log forensics system that is named, SecureLog. The deterministic rule based signature engine that is used by SecureLog is achieved through optimized regular expression matching to make decisions on classification that are transparent and reproducible. Once every malicious request is identified it is categorized, summarized in plaintext and hashed with the SHA-256 cryptographic hash at ingestion in order to guarantee verifiable forensic integrity. This was experimented using the official test set of the CSIC 2010 HTTP Dataset that had 61,065 HTTP request(s) (36,000 benign, 25,065 anomalous). The accuracy of detection (91.67), FalsePositiveRate (0) and processing latency (roughly 0.0113 ms per request) are ultra-low as shown experimentally. SecureLog offers a legal and computationally-efficient substitute to the probabilistic generalization, which might be applicable in the low scale web infrastructure environments by prioritizing the features of availability, interpretability, and deterministic behavior.
关键词
Web Attack Detection System
稿件作者
Ramya Shree M
Christ University
Addapalli Krishna V N Krishna
CHRIST UNIVERSITY
E Baburaj
Christ University Bangalore
发表评论