METHOD FOR DETECTING ANOMALOUS HTTP REQUESTS USING A RECURRENT NEURAL NETWORK BASED ON A SESSION SUSPICION INDEX
DOI:
https://doi.org/10.18372/2310-5461.71.21454Keywords:
anomaly detection, HTTP requests, neural network, web application security, session suspicion index, CSIC 2010, class imbalanceAbstract
This paper investigates the task of detecting anomalous HTTP requests in web traffic using a recurrent neural network, which remains a relevant direction in web application security given the steadily growing volume and diversity of application-layer attacks. The network is trained on the real HTTP DATASET CSIC 2010 and classifies individual requests as normal or anomalous based on the character-level representation of the request text, enabling detection of both known and previously unseen malicious payload variants without dependence on a signature database. Since operational response decisions at the web application level are typically made not with respect to an individual request but with respect to the user session as a whole, this paper proposes a session suspicion index (SSI) metric that aggregates character-level anomaly scores of a session’s requests, accounting for both the single most dangerous request and distributed suspicious activity that is not concentrated in any individual request. The metric provides a calibrated session-level score within the range from 0 to 1 regardless of session length, and its weighting coefficients are justified based on the cost ratio of type I and type II errors. Since the CSIC 2010 dataset does not contain a natural multi-request session structure, sessions were constructed from the dataset’s real requests and real labels according to three user behavior scenarios, covering both legitimate activity and typical automated vulnerability scanner behavior. The recurrent network was implemented without relying on third-party deep learning frameworks, which ensures full control over the computational process and transparency of the architecture. The SSI results are compared against baseline session scoring rules based on the maximum and mean values of request anomaly scores, and the robustness of the results is verified through a sensitivity analysis of the metric parameters.
References
1. Liang J., Zhao W., Ye W. Anomaly-Based Web Attack Detection: A Deep Learning Approach // Proceedings of the 2017 VI International Conference on Network, Communication and Computing (ICNCC 2017). New York : ACM, 2017. P. 80–85.
2. Radford B. J., Apolonio L. M., Trias A. J., Simpson J. A. Network Traffic Anomaly Detection Using Recurrent Neural Networks // arXiv preprint. 2018. arXiv:1803.10769.
3. Gui J., Chen Z., Yu X., Lumezanu C., Chen H. Anomaly Detection on Web-User Behaviors Through Deep Learning // Security and Privacy in Communication Networks : SecureComm 2020 : Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommuni-cations Engineering, vol. 335. Cham : Springer, 2020.
4. Luo K., Chen Y. A Novel Hybrid Neural Network Approach Incorporating Convolution and LSTM With a Self-Attention Mechanism for Web Attack Detection // Applied Intelligence. 2024.
5. Torrano-Gimenez C., Perez-Villegas A., Alvarez Maranon G. An Anomaly-Based Approach for Intrusion Detection in Web Traffic // Journal of Information Assurance and Security. 2010. Vol. 5, No. 4. P. 446–454.
6. Pevný T., Dedíč M. Nested Multiple Instance Learning in Modelling of HTTP Network Traffic // arXiv preprint. 2020. arXiv:2002.04059.
7. Instituto de Tecnologías Físicas y de la Información (ITEFI), CSIC. HTTP DATASET CSIC 2010. Madrid, 2010. URL: https://www.tic.itefi.csic.es/ dataset/
8. Elman J. L. Finding Structure in Time // Cognitive Science. 1990. Vol. 14, No. 2. P. 179–211.
9. Pedregosa F., Varoquaux G., Gramfort A., Michel V., Thirion B., Grisel O., Blondel M., Prettenhofer P., Weiss R., Dubourg V., Vanderplas J., Passos A., Cournapeau D., Brucher M., Perrot M., Duchesnay É. Scikit-learn: Machine Learning in Python // Journal of Machine Learning Research. 2011. Vol. 12. P. 2825–2830.
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Г Пекуровський

This work is licensed under a Creative Commons Attribution 4.0 International License.
The scientific journal adheres to the principles of Open Access and provides free, immediate, and permanent access to all published materials without financial, technical, or legal barriers for readers.
All articles are published in Open Access under the Creative Commons Attribution 4.0 International (CC BY 4.0) license.
Copyright
Authors who publish their works in the journal:
-
retain the copyright to their publications;
-
grant the journal the right of first publication of the article;
-
agree to the distribution of their materials under the CC BY 4.0 license;
-
have the right to reuse, archive, and distribute their works (including in institutional and subject repositories), provided that proper reference is made to the original publication in the journal.



