{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,7,30]],"date-time":"2025-07-30T09:44:22Z","timestamp":1753868662970,"version":"3.41.2"},"reference-count":19,"publisher":"Wiley","issue":"20","license":[{"start":{"date-parts":[[2016,8,2]],"date-time":"2016-08-02T00:00:00Z","timestamp":1470096000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/2.zoppoz.workers.dev:443\/http\/onlinelibrary.wiley.com\/termsAndConditions#vor"}],"funder":[{"name":"Strategic Priority Research Program of the Chinese Academy of Sciences","award":["XDA06030200"],"award-info":[{"award-number":["XDA06030200"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Concurrency and Computation"],"published-print":{"date-parts":[[2017,10,25]]},"abstract":"<jats:title>Summary<\/jats:title><jats:p>In recent years, more and more intrusion detection systems and firewalls have been used to detect and block malicious applications or unknown protocols in order to enhance the security of systems. Therefore, some malicious applications begin to shape themselves as common ones to escape malicious protocol detection. Being an important protocol for many Internet services, hypertext transfer protocol (HTTP) is responsible for nearly 10% of the traffic volume on the Internet. Therefore, many malicious applications pretend their traffic to be HTTP protocol to go into hiding their malicious behaviors. In the paper, we study the problem of discovering these abnormal behaviors in HTTP protocol traffic. We find that the characteristics of many abnormal behaviors are performed in the header fields of their shaping HTTP such as Tor and malicious web crawlers, and the information of HTTP header fields of HTTP traffic generated by normal application is also discussed. And then, a method based on the measurement of HTTP header fields proposed three patterns that make them specific to detect abnormal behaviors of shaping HTTP protocol. The experimental results indicate that the proposed method is effective for abnormal behaviors by shaping to be HTTP on large\u2010scale traffic of one Internet service provider. The experimental results also show that the proposed method could be extended to large\u2010scale and high\u2010speed network environment for detecting abnormal behaviors of shaping HTTP protocol. Copyright \u00a9 2016 John Wiley &amp; Sons, Ltd.<\/jats:p>","DOI":"10.1002\/cpe.3926","type":"journal-article","created":{"date-parts":[[2016,8,2]],"date-time":"2016-08-02T23:22:43Z","timestamp":1470180163000},"source":"Crossref","is-referenced-by-count":5,"title":["Discovering abnormal behaviors via HTTP header fields measurement"],"prefix":"10.1002","volume":"29","author":[{"given":"Gaopeng","family":"Gou","sequence":"first","affiliation":[{"name":"Institute of Information Engineering Chinese Academy of Sciences  Minzhuang Road #89, Haidian Beijing China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Quan","family":"Bai","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering Chinese Academy of Sciences  Minzhuang Road #89, Haidian Beijing China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Gang","family":"Xiong","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering Chinese Academy of Sciences  Minzhuang Road #89, Haidian Beijing China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhenzhen","family":"Li","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering Chinese Academy of Sciences  Minzhuang Road #89, Haidian Beijing China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"311","published-online":{"date-parts":[[2016,8,2]]},"reference":[{"key":"e_1_2_7_2_1","unstructured":"HjelmvikE JohnW.Breaking and improving protocol obfuscation. In Chalmers University of Technology 2010."},{"key":"e_1_2_7_3_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.istr.2005.07.003"},{"key":"e_1_2_7_4_1","unstructured":"HoumansadrA RiedlT BorisovN SingerA.I want my voice to be heard: IP over voice\u2010over\u2010IP for unobservable censorship circumvention. InProceedings of the 20th Annual Network & Distributed System Security Symposium (NDSS):San Diego CA 2013;1\u201317."},{"key":"e_1_2_7_5_1","unstructured":"BrumleyBB ValkonenJ.Attacks on message stream encryption."},{"key":"e_1_2_7_6_1","doi-asserted-by":"crossref","unstructured":"DyerKP CoullSE RistenpartT ShrimptonT.Protocol misidentification made easy with format\u2010transforming encryption. InProceedings of the ACM Conference on Computer and Communications Security.ACM Berlin Germany 2013;61\u201372.","DOI":"10.1145\/2508859.2516657"},{"key":"e_1_2_7_7_1","first-page":"(494): 1","article-title":"Format\u2010transforming encryption: more than meets the DPI","author":"Dyer KP","year":"2012","journal-title":"IACR Cryptology ePrint Archive"},{"key":"e_1_2_7_8_1","unstructured":"Available from: https:\/\/2.zoppoz.workers.dev:443\/https\/www.sandvine.com\/downloads\/general\/global\u2010internet\u2010phenomena\/2014\/1h\u20102014\u2010global\u2010internet\u2010phenomena\u2010report.pdf."},{"key":"e_1_2_7_9_1","doi-asserted-by":"crossref","unstructured":"ZanderS NguyenT ArmitageG.Automated traffic classification application identification using machine learning 2005;250\u2013257.","DOI":"10.1109\/LCN.2005.35"},{"key":"e_1_2_7_10_1","unstructured":"DharmapurikarS KrishnamurthyP SproullTS LockwoodJW.Deep packet inspection using parallel Bloom filters. InProceedings of the 11th Symposium on High Performance Interconnects.IEEE 2003;44\u201351."},{"key":"e_1_2_7_11_1","doi-asserted-by":"crossref","unstructured":"BaiQ XiongG ZhaoY LiZZ.Discover abnormal behaviors using HTTP header fields measurement. InProceedings of the Applications and Techniques in Information Security ATIS:Beijing China 2015;89\u2013100.","DOI":"10.1007\/978-3-662-48683-2_9"},{"key":"e_1_2_7_12_1","doi-asserted-by":"crossref","unstructured":"BaiQ XiongG ZhaoY.Find behaviors of network evasion and protocol obfuscation using traffic measurement. InProceedings of the International Standard Conference on Trustworthy Computing and Services (ISCTCS).Springer:Beijing China 2014;342\u2013349.","DOI":"10.1007\/978-3-662-47401-3_45"},{"issue":"2","key":"e_1_2_7_13_1","first-page":"278","article-title":"Automatic network protocol analysis and vulnerability discovery based on symbolic expression","volume":"30","author":"Luo C","year":"2013","journal-title":"Journal of Graduate University of Chinese Academy of Sciences"},{"key":"e_1_2_7_14_1","doi-asserted-by":"crossref","unstructured":"CaballeroJ YinH LiangZ SongD.Polyglot: automatic extraction of protocol message format using dynamic binary analysis. InProceedings of the 14th ACM Conference on Computer and Communications Security.ACM Alexandriava VA 2007;317\u2013329.","DOI":"10.1145\/1315245.1315286"},{"key":"e_1_2_7_15_1","unstructured":"RoelkerDJ.HTTP IDS evasions revisited. Sourcefire Inc 2004."},{"key":"e_1_2_7_16_1","doi-asserted-by":"crossref","unstructured":"MahoneyMV ChanPK.Learning nonstationary models of normal network traffic for detecting novel attacks. InProceedings of the 8th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining.ACM Edmonton Canada 2002;376\u2013385.","DOI":"10.1145\/775047.775102"},{"key":"e_1_2_7_17_1","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"203","DOI":"10.1007\/978-3-540-30143-1_11","volume-title":"Recent Advances in Intrusion Detection","author":"Wang K","year":"2004"},{"key":"e_1_2_7_18_1","unstructured":"HjelmvikE JohnW.Statistical protocol identification with SPID: preliminary results. InProceedings of the Swedish National Computer Networking Workshop:Uppsala Sweden 2009;1\u20135."},{"volume-title":"A Implementation of Intrusion Detection System Based on Web Anomaly Detection","year":"2010","author":"Shen X","key":"e_1_2_7_19_1"},{"key":"e_1_2_7_20_1","doi-asserted-by":"crossref","unstructured":"HoumansadrA BrubakerC ShmatikovV.The parrot is dead: observing unobservable network communications. InProceedings of the IEEE Symposium on Security and Privacy (SP):Berkeley California USA 2013;65\u201379.","DOI":"10.1109\/SP.2013.14"}],"container-title":["Concurrency and Computation: Practice and Experience"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/api.wiley.com\/onlinelibrary\/tdm\/v1\/articles\/10.1002%2Fcpe.3926","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/api.wiley.com\/onlinelibrary\/tdm\/v1\/articles\/10.1002%2Fcpe.3926","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/onlinelibrary.wiley.com\/doi\/pdf\/10.1002\/cpe.3926","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,9,11]],"date-time":"2023-09-11T22:25:41Z","timestamp":1694471141000},"score":1,"resource":{"primary":{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/onlinelibrary.wiley.com\/doi\/10.1002\/cpe.3926"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016,8,2]]},"references-count":19,"journal-issue":{"issue":"20","published-print":{"date-parts":[[2017,10,25]]}},"alternative-id":["10.1002\/cpe.3926"],"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1002\/cpe.3926","archive":["Portico"],"relation":{},"ISSN":["1532-0626","1532-0634"],"issn-type":[{"type":"print","value":"1532-0626"},{"type":"electronic","value":"1532-0634"}],"subject":[],"published":{"date-parts":[[2016,8,2]]},"article-number":"e3926"}}