Presentation 2017-03-14
Attack Pattern Extraction by Clustering Parameters
Shingo Orihara, Tohru Sato, Masaki Tanikawa,
PDF Download Page PDF download Page Link
Abstract(in Japanese) (See Japanese page)
Abstract(in English) Web Application Firewall (WAF) is widely used to detect attacks against Web applications. New sorts of attacks occurs day by day and to detect such new attacks, it is required to update WAF signatures continuously. In this paper we introduce our method to extract attack patterns by clustering HTTP request parameters which may contain attack codes. Experimental result shows that our method has capabilities to extract several attack patterns which are likely real attacks.
Keyword(in Japanese) (See Japanese page)
Keyword(in English) Web Application / WAF / Signature / Longest Common Subsequence (LCS)
Paper # ICSS2016-60
Date of Issue 2017-03-06 (ICSS)

Conference Information
Committee ICSS / IPSJ-SPT
Conference Date 2017/3/13(2days)
Place (in Japanese) (See Japanese page)
Place (in English) University of Nagasaki
Topics (in Japanese) (See Japanese page)
Topics (in English) System Security, etc.
Chair Yutaka Miyake(KDDI R&D Labs.)
Vice Chair Yoshiaki Shiraishi(Kobe Univ.) / Takeshi Ueda(Mitsubishi Electric)
Secretary Yoshiaki Shiraishi(NII) / Takeshi Ueda(Yokohama National Univ.)
Assistant Kazunori Kamiya(NTT) / Takahiro Kasama(NICT)

Paper Information
Registration To Technical Committee on Information and Communication System Security / Special Interest Group on Security Psychology and Trust
Language JPN
Title (in Japanese) (See Japanese page)
Sub Title (in Japanese) (See Japanese page)
Title (in English) Attack Pattern Extraction by Clustering Parameters
Sub Title (in English)
Keyword(1) Web Application
Keyword(2) WAF
Keyword(3) Signature
Keyword(4) Longest Common Subsequence (LCS)
1st Author's Name Shingo Orihara
1st Author's Affiliation Nippon Telegraph and Telephone Corporation(NTT)
2nd Author's Name Tohru Sato
2nd Author's Affiliation Nippon Telegraph and Telephone Corporation(NTT)
3rd Author's Name Masaki Tanikawa
3rd Author's Affiliation Nippon Telegraph and Telephone Corporation(NTT)
Date 2017-03-14
Paper # ICSS2016-60
Volume (vol) vol.116
Number (no) ICSS-522
Page pp.pp.123-128(ICSS),
#Pages 6
Date of Issue 2017-03-06 (ICSS)