<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE ArticleSet PUBLIC "-//NLM//DTD PubMed 2.7//EN" "https://dtd.nlm.nih.gov/ncbi/pubmed/in/PubMed.dtd">
<ArticleSet>
<Article>
<Journal>
				<PublisherName>Iranian Society of Cryptology</PublisherName>
				<JournalTitle>The ISC International Journal of Information Security</JournalTitle>
				<Issn>2008-2045</Issn>
				<Volume>12</Volume>
				<Issue>1</Issue>
				<PubDate PubStatus="epublish">
					<Year>2020</Year>
					<Month>01</Month>
					<Day>01</Day>
				</PubDate>
			</Journal>
<ArticleTitle>Anomaly-based Web Attack Detection: The Application of Deep Neural Network Seq2Seq With Attention Mechanism</ArticleTitle>
<VernacularTitle></VernacularTitle>
			<FirstPage>44</FirstPage>
			<LastPage>54</LastPage>
			<ELocationID EIdType="pii">101909</ELocationID>
			
<ELocationID EIdType="doi">10.22042/isecure.2020.199009.479</ELocationID>
			
			<Language>EN</Language>
<AuthorList>
<Author>
					<FirstName>Shahriar</FirstName>
					<LastName>Mohammadi</LastName>
<Affiliation>associate professor in Khajeh Nasir Toosi University of Technology</Affiliation>

</Author>
<Author>
					<FirstName>Amin</FirstName>
					<LastName>Namadchian</LastName>
<Affiliation>phd candidate in industrial engineering of Khajeh Nasir Toosi University of Technology., Tehran, Iran</Affiliation>

</Author>
</AuthorList>
				<PublicationType>Journal Article</PublicationType>
			<History>
				<PubDate PubStatus="received">
					<Year>2019</Year>
					<Month>08</Month>
					<Day>23</Day>
				</PubDate>
			</History>
		<Abstract>Today, the use of the Internet and Internet sites has been an integrated part of the people’s lives, and most activities and important data are in the Internet websites. Thus, attempts to intrude into these websites have grown exponentially. Intrusion detection systems (IDS) of web attacks are an approach to protect users. But, these systems are suffering from such drawbacks as low accuracy in detecting new attacks. To tackle this problem, various methods of machine learning have been presented in recent years. Since malicious web requests have more delicate distinction than normal requests, these methods have failed to exhibit a good accuracy in new attack detection. This paper presents a new method for web attack detection using seq2seq networks using attention. The results show that this method could predict the possible responses and use the difference from the real responses of the server to model the normal traffic. Thereby, it could use the similarity measure to discriminate between normal and anomalous traffic. The highest accuracy of this method versus similar methods shows that the use of attention mechanism can cope with the challenge of studying long web requests to a great extent.</Abstract>
		<ObjectList>
			<Object Type="keyword">
			<Param Name="value">Deep seq2seq network</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">web intrusion detection system</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">attention mechanism</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">Embedding</Param>
			</Object>
		</ObjectList>
<ArchiveCopySource DocType="pdf">https://www.isecure-journal.com/article_101909_9d2f80888863df107c8151aa5e37ce4b.pdf</ArchiveCopySource>
</Article>
</ArticleSet>
