Skip to main navigation Skip to search Skip to main content

A Quantitative Approach for Threat Assessment from Heterogeneous Web Security Logs

  • Wenying Feng
  • , Cui Luo
  • , Ze Zhu
  • , Xiayu Xiang
  • , Ke Zhou
  • , Zhaoquan Gu*
  • *Corresponding author for this work
  • Pengcheng Laboratory
  • Harbin Institute of Technology Shenzhen

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Intrusion detection systems (IDS) and web application firewalls (WAF) generate overwhelming volumes of alerts, yet lack fine-grained threat assessment capabilities to identify valuable alert clues or high-risk threat events from them. Regarding this problem, we propose a Regression-based fine-grained Threat Assessment Framework called RegTAF for evaluating and analyzing threats in multi-source Web security logs. RegTAF extracts threat entities (e.g., security events and malicious IPs) and characterizes them along multiple dimensions. To overcome label scarcity and severe class imbalance in security logs, we employ unsupervised representation learning to enhance feature discriminability. A regression model is then trained to output the assessment of threat severity, enabling precise risk quantification for security events. Through ablation studies and comparative experiments across multiple regression algorithms, we validate the effectiveness of RegTAF, identify the key threat dimensions governing severity assessment, and provide complexity analysis with different regression algorithms. By implementing RegTAF, high-threat or potentially harmful threat entities can be selected based on fine-grained threat severity, thereby improving the efficiency of web attack detection analysis.

Original languageEnglish
Title of host publicationKnowledge Science, Engineering and Management - 19th International Conference, KSEM 2026, Proceedings
EditorsJianwei Niu, Meikang Qiu, Cungen Cao
PublisherSpringer Science and Business Media Deutschland GmbH
Pages118-128
Number of pages11
ISBN (Print)9789819228676
DOIs
StatePublished - 2027
Externally publishedYes
Event19th International Conference on Knowledge Science, Engineering and Management, KSEM 2026 - Beijing, China
Duration: 17 Jul 202619 Jul 2026

Publication series

NameLecture Notes in Computer Science
Volume16637 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference19th International Conference on Knowledge Science, Engineering and Management, KSEM 2026
Country/TerritoryChina
CityBeijing
Period17/07/2619/07/26

Keywords

  • Intrusion detection
  • Regression analysis
  • Threat assessment
  • Web attack detection

Fingerprint

Dive into the research topics of 'A Quantitative Approach for Threat Assessment from Heterogeneous Web Security Logs'. Together they form a unique fingerprint.

Cite this