METHOD FOR DETECTING ANOMALOUS HTTP REQUESTS USING A RECURRENT NEURAL NETWORK BASED ON A SESSION SUSPICION INDEX

Authors

DOI:

https://doi.org/10.18372/2310-5461.71.21454

Keywords:

anomaly detection, HTTP requests, neural network, web application security, session suspicion index, CSIC 2010, class imbalance

Abstract

This paper investigates the task of detecting anomalous HTTP requests in web traffic using a recurrent neural network, which remains a relevant direction in web application security given the steadily growing volume and diversity of application-layer attacks. The network is trained on the real HTTP DATASET CSIC 2010 and classifies individual requests as normal or anomalous based on the character-level representation of the request text, enabling detection of both known and previously unseen malicious payload variants without dependence on a signature database. Since operational response decisions at the web application level are typically made not with respect to an individual request but with respect to the user session as a whole, this paper proposes a session suspicion index (SSI) metric that aggregates character-level anomaly scores of a session’s requests, accounting for both the single most dangerous request and distributed suspicious activity that is not concentrated in any individual request. The metric provides a calibrated session-level score within the range from 0 to 1 regardless of session length, and its weighting coefficients are justified based on the cost ratio of type I and type II errors. Since the CSIC 2010 dataset does not contain a natural multi-request session structure, sessions were constructed from the dataset’s real requests and real labels according to three user behavior scenarios, covering both legitimate activity and typical automated vulnerability scanner behavior. The recurrent network was implemented without relying on third-party deep learning frameworks, which ensures full control over the computational process and transparency of the architecture. The SSI results are compared against baseline session scoring rules based on the maximum and mean values of request anomaly scores, and the robustness of the results is verified through a sensitivity analysis of the metric parameters.

Author Biographies

Hlib Pekurovskyi, National University "Kyiv Aviation Institute", Kyiv, Ukraine

Candidate of Technical Sciences

Serhii Lazarenko, National University "Kyiv Aviation Institute", Kyiv, Ukraine

Doctor of Technical Sciences, Professor

References

1. Liang J., Zhao W., Ye W. Anomaly-Based Web Attack Detection: A Deep Learning Approach // Proceedings of the 2017 VI International Conference on Network, Communication and Computing (ICNCC 2017). New York : ACM, 2017. P. 80–85.

2. Radford B. J., Apolonio L. M., Trias A. J., Simpson J. A. Network Traffic Anomaly Detection Using Recurrent Neural Networks // arXiv preprint. 2018. arXiv:1803.10769.

3. Gui J., Chen Z., Yu X., Lumezanu C., Chen H. Anomaly Detection on Web-User Behaviors Through Deep Learning // Security and Privacy in Communication Networks : SecureComm 2020 : Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommuni-cations Engineering, vol. 335. Cham : Springer, 2020.

4. Luo K., Chen Y. A Novel Hybrid Neural Network Approach Incorporating Convolution and LSTM With a Self-Attention Mechanism for Web Attack Detection // Applied Intelligence. 2024.

5. Torrano-Gimenez C., Perez-Villegas A., Alvarez Maranon G. An Anomaly-Based Approach for Intrusion Detection in Web Traffic // Journal of Information Assurance and Security. 2010. Vol. 5, No. 4. P. 446–454.

6. Pevný T., Dedíč M. Nested Multiple Instance Learning in Modelling of HTTP Network Traffic // arXiv preprint. 2020. arXiv:2002.04059.

7. Instituto de Tecnologías Físicas y de la Información (ITEFI), CSIC. HTTP DATASET CSIC 2010. Madrid, 2010. URL: https://www.tic.itefi.csic.es/ dataset/

8. Elman J. L. Finding Structure in Time // Cognitive Science. 1990. Vol. 14, No. 2. P. 179–211.

9. Pedregosa F., Varoquaux G., Gramfort A., Michel V., Thirion B., Grisel O., Blondel M., Prettenhofer P., Weiss R., Dubourg V., Vanderplas J., Passos A., Cournapeau D., Brucher M., Perrot M., Duchesnay É. Scikit-learn: Machine Learning in Python // Journal of Machine Learning Research. 2011. Vol. 12. P. 2825–2830.

Published

2026-09-10

How to Cite

Pekurovskyi, H., Lazarenko, S., & Kutinov, O. (2026). METHOD FOR DETECTING ANOMALOUS HTTP REQUESTS USING A RECURRENT NEURAL NETWORK BASED ON A SESSION SUSPICION INDEX. Science-Based Technologies, 71(3), 382–391. https://doi.org/10.18372/2310-5461.71.21454

Issue

Section

Information technology and electronics