Skip to content

Web Application Attack Detection Methodology Based on a Combination of Gradient Boosting, Transformers, and Neural Networks

Aug 2026 · PROGRAMMNAYA INGENERIA · 0 citations

Abstract

The growing number of attacks on web applications and the increasing volume of HTTP traffic strengthen the requirements for automatic malware detection systems. The aim of the research is to develop a technique for detecting attacks on web applications based on a cascade approach, which allows combining a quick initial analysis of incoming requests with a more detailed classification of potentially dangerous traffic. The proposed methodology is based on the sequential (step-by-step) application of two models that differ in purpose and computational complexity. The first stage performs binary filtering of HTTP requests and is designed to promptly exclude legitimate traffic from further processing. The second stage applies only to requests deemed suspicious and solves the task of multiclass classification by identifying the type of attack. Due to this separation, resource-intensive processing is not used for the entire data stream, but only for its most significant part, which reduces the computational load of the system. The paper also presents a technique for detecting attacks on web applications, describing the full cycle of building and applying the proposed cascade model. It allows us to consider the model not only as an experimental solution, but also as a consistent procedure suitable for practical implementation. Experimental verification of the proposed approach demonstrates that the cascading organization of the analysis makes it possible to reduce the number of requests submitted for in-depth verification without significantly reducing the ability of the model to detect malicious requests. The proposed approach is aimed at eliminating one of the significant limitations of existing solutions, which is the gap between the high quality of classification and the practical applicability of the model when processing an intensive stream of HTTP requests.

View source

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.