Detecting and Explaining Anomalies Caused by Web Tamper Attacks via Building Consistency-based Normality
Yifan Liao, Ming Xu, Yun Lin, Xiwen Teoh, Xiaofei Xie, Ruitao Feng, Frank Liaw, Hongyu Zhang, Jin Song Dong
Abstract
Web applications are crucial infrastructures in the modern society, which have high demand of reliability and security. However, their frontend can be manipulable by the clients (e.g., the frontend code can be modified to bypass some validation steps), which incurs the runtime anomaly when operating the web service. Existing state-of-the-art anomaly detectors largely learn a deep learning model from the collected logs to predict abnormal logs with a probability. While effective in general, those approaches can suffer from (1) inaccuracy caused by subtle difference between the normal and abnormal/attack logs and (2) additional efforts for root cause analysis. In this work, we propose WebNorm, an anomaly detection approach to detect and explain the attack-caused anomalies on web applications in a unified way. Our rationale lies in learning the behaviorial normalities of a running web application as invariants. The normalities are designed regarding data normality (e.g., what information must be consistent across different events), flow normality (e.g., what events must happen under certain circumstances), and common-sense normality (e.g., what is the normal range of some parameters). The violation of the invariants indicates both the alarm and its explanation. WebNorm first monitors the normal # Both authors contributed equally to the paper.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 14202e63-3acd-4d7d-8b91-d82345a79e94Cited by top-tier papers2
- Reflections on the Reproducibility of Commercial LLM Performance in Empirical Software Engineering StudiesFlorian Angermeir, Maximilian Amougou, Mark Kreitz, Andreas Bauer et al.ICSE 2026 · 1 citation
- MINES: Explainable Anomaly Detection through Web API Invariant InferenceWenjie Zhang, Yun Lin, Chun Fung Amos Kwok, Xiwen Teoh et al.ICSE 2026
Builds on13
- DeepLog: Anomaly Detection and Diagnosis from System Logs through Deep LearningMin Du, Feifei Li, Guineng Zheng, Vivek SrikumarCCS 2017 · 1,823 citations
- Log-based Anomaly Detection Without Log ParsingVan-Hoang Le, Hongyu ZhangASE 2021 · 249 citations
- Log-based Anomaly Detection with Deep Learning: How Far Are We?Van-Hoang Le, Hongyu ZhangICSE 2022 · 212 citations
- DeepTraLog: Trace-Log Combined Microservice Anomaly Detection through Graph-based Deep LearningChenxi Zhang, Xin Peng, Chaofeng Sha, Ke Zhang et al.ICSE 2022 · 163 citations
- Identifying bad software changes via multimodal anomaly detection for online service systemsNengwen Zhao, Junjie Chen, Zhaoyang Yu, Honglin Wang et al.FSE 2021 · 89 citations
Related papers
- Achieving Interpretable DL-based Web Attack Detection through Malicious Payload LocalizationPeiyang Li, Fukun Mei, Ye Wang, Zhuotao Liu et al.NDSS 2026
- Anomaly Detection in the Open World: Normality Shift Detection, Explanation, and AdaptationDongqi Han, Zhiliang Wang, Wenqi Chen, Kai Wang et al.NDSS 2023
- LogOnline: A Semi-Supervised Log-Based Anomaly Detector Aided with Online Learning MechanismXuheng Wang, Jiaxing Song, Xu Zhang, Junshu Tang et al.ASE 2023 · 12 citations
- Reliability Assurance for Deep Neural Network Architectures Against Numerical DefectsLinyi Li, Yuhao Zhang, Luyao Ren, Yingfei Xiong et al.ICSE 2023 · 7 citations
- Reimagining Anomalies: What If Anomalies Were Normal?Philipp Liznerski, Saurabh Varshneya, Ece Calikus, Puyu Wang et al.AAAI 2026 · 4 citations
