We gratefully acknowledge support from
the Simons Foundation and member institutions.
Full-text links:

Download:

Current browse context:

cs.CR

Change to browse by:

References & Citations

DBLP - CS Bibliography

Bookmark

(what is this?)
CiteULike logo BibSonomy logo Mendeley logo del.icio.us logo Digg logo Reddit logo

Computer Science > Cryptography and Security

Title: Anomaly Detection in XML-Structured SOAP Messages Using Tree-Based Association Rule Mining

Abstract: Web services are software systems designed for supporting interoperable dynamic cross-enterprise interactions. The result of attacks to Web services can be catastrophic and causing the disclosure of enterprises' confidential data. As new approaches of attacking arise every day, anomaly detection systems seem to be invaluable tools in this context. The aim of this work has been to target the attacks that reside in the Web service layer and the extensible markup language (XML)-structured simple object access protocol (SOAP) messages. After studying the shortcomings of the existing solutions, a new approach for detecting anomalies in Web services is outlined. More specifically, the proposed technique illustrates how to identify anomalies by employing mining methods on XML-structured SOAP messages. This technique also takes the advantages of tree-based association rule mining to extract knowledge in the training phase, which is used in the test phase to detect anomalies. In addition, this novel composition of techniques brings nearly low false alarm rate while maintaining the detection rate reasonably high, which is shown by a case study.
Comments: Trustworthy Computing Laboratory, School of Computer Engineering, Iran University of Science and Technology
Subjects: Cryptography and Security (cs.CR); Artificial Intelligence (cs.AI)
Report number: Technical Report No. TWcL-TR-1501, Trustworthy Computing Laboratory, School of Computer Engineering, Iran University of Science and Technology, Tehran, Iran, 2015
Cite as: arXiv:1605.06466 [cs.CR]
  (or arXiv:1605.06466v1 [cs.CR] for this version)

Submission history

From: Mohammad Abdollahi Azgomi Dr. [view email]
[v1] Fri, 20 May 2016 18:43:44 GMT (1275kb)

Link back to: arXiv, form interface, contact.