WebTrap: Uma ferramenta de detecção de ataques em requisições HTTP utilizando Aprendizado de Máquina

Resumo


Segundo o relatório OWASP Top 10 2025, vulnerabilidades do tipo Injection permanecem entre os principais riscos de segurança para aplicações web. Este trabalho propõe um honeypot web que integra dois modelos de aprendizado de máquina a mecanismos de deception. O primeiro modelo identifica requisições HTTP associadas aos ataques SQL Injection, Cross-Site Scripting, Remote Code Execution e Local File Inclusion, distinguindo-as do tráfego benigno, enquanto o segundo classifica a categoria do ataque detectado. Os resultados indicaram taxas de detecção superiores a 94% para tráfego malicioso gerado por ferramentas como sqlmap, XSSER, Commix e Wfuzz. Para requisições benignas, foi obtida uma taxa de acerto de aproximadamente 93%, evidenciando a viabilidade da abordagem proposta para honeypots web inteligentes.

Referências

Ali, R. H. and Karam, Z. S. (2026). Enhancing performance of intrusion prevention systems through machine learning: A comparative study. Baghdad Science Journal.

Buczak, A. L. and Guven, E. (2016). A survey of data mining and machine learning methods for cyber security intrusion detection. IEEE Communications Surveys & Tutorials, 18(2):1153–1176.

Canadian Institute for Cybersecurity. Intrusion detection evaluation dataset (cic-ids2017). Disponível em [link]. Acessado em maio de 2026.

Correia, P. H. B. and Pedrini, H. (2020). Detecção de domínios maliciosos baseada em técnicas de aprendizado de máquina. Trabalho de conclusão de curso (Bacharelado em Ciência da Computação). Universidade Estadual de Campinas.

Damele, B. and Stampar, M. sqlmap: Automatic sql injection and database takeover tool. [link].

danielmiessler. Seclists. Disponível em [link]. Acessado em maio de 2026.

EPSYLON. Xsser: Cross site "scripter". [link].

Faisal Fadlalla, F. and Elshoush, H. T. (2023). Input validation vulnerabilities in web applications: Systematic review, classification, and analysis of the current state-of-the-art. IEEE Access, 11:40128–40161.

Farzaan, M. A. M., Ghanem, M. C., El-Hajjar, A., and Ratnayake, D. N. (2024). Ai-enabled system for efficient and effective cyber incident detection and response in cloud environments. arXiv preprint arXiv:2404.05602.

Guarizi, B., Mascarenhas, D., and Moraes, I. (2025). Phishing guardian: Detecção de sites de phishing com machine learning. In Anais do XXV Simpósio Brasileiro de Cibersegurança, pages 693–709, Porto Alegre, RS, Brasil. SBC.

IBM. X-force threat intelligence index 2026. Disponível em [link]. Acessado em maio de 2026.

Kaya, M. O., Dagdogen, H. A., Ozdem, M., and Das, R. (2026). An effective new penetration test approach to detect web attacks on web applications. Expert Systems with Applications, 298:129623.

Komiya, R., Paik, I., and Hisada, M. (2011). Classification of malicious web code by machine learning. In 2011 3rd International Conference on Awareness Science and Technology (iCAST), pages 406–411.

López, P. B., Pérez, M. G., and Nespoli, P. (2024). Cyber deception: State of the art, trends and open challenges.

Matthew Sudol. Web-application-attack-datasets. Disponível em [link]. Acessado em maio de 2026.

McNally, S. and Curran, K. (2024). Web application vulnerabilities.

Nimmagadda, A. and Mehr, S. Y. (2025). Ai-powered intrusion detection system with honeypot integration. International Journal of Intelligent Information Systems.

Noman, M., Iqbal, M., and Manzoor, E. D. A. (2020). A survey on detection and prevention of web vulnerabilities. International Journal of Advanced Computer Science and Applications, 11:521–540.

OWASP Foundation. Owasp top 10:2025. Disponível em [link]. Acessado em maio de 2026.

Palo Alto Networks. 2026 unit 42 global incident response report - palo alto networks. Disponível em [link]. Acessado em maio de 2026.

pedro-hfw. Webtrap. Disponível em [link]. Acessado em julho de 2026.

Rahman, M. (2025). Cross-domain semi-supervised detection of zero-day web application attacks via multi-modal http request and payload features.

Rong, W., Zhang, B., and Lv, X. (2018). Malicious web request detection using character-level cnn.

Sayari, A. and Rekhis, S. (2025). Cyber deception across domains: A comprehensive survey of techniques, challenges, and perspectives. International Journal of Advanced Computer Science and Applications, 16(7).

Sen, R., Heim, G., and Zhu, Q. (2022). Artificial intelligence and machine learning in cybersecurity: Applications, challenges, and opportunities for mis academics. Communications of the Association for Information Systems, 51:pp–pp.

Sharif, M. H. U. (2022). Web attacks analysis and mitigation techniques. International Journal of Engineering Research & Technology (IJERT).

Stasinopoulos, A., Ntantogian, C., and Xenakis, C. (2019). Commix: automating evaluation and exploitation of command injection vulnerabilities in web applications. Int. J. Inf. Secur., 18(1):49–72.

swisskyrepo. Payloadsallthethings. Disponível em [link]. Acessado em maio de 2026.

Thang, N. M. (2020). Improving efficiency of web application firewall to detect code injection attacks with random forest method and analysis attributes http request. Programming and Computer Software, 46(5):351–361.

xmendez. Wfuzz - the web fuzzer". [link].

Zhang, F., Zhou, S., Qin, Z., and Liu, J. (2003). Honeypot: a supplemented active defense system for network security. In Proceedings of the Fourth International Conference on Parallel and Distributed Computing, Applications and Technologies, pages 231–235.

Zhang, J., Zulkernine, M., and Haque, A. (2008). Random-forests-based network intrusion detection systems. IEEE Transactions on Systems, Man, and Cybernetics, Part C (Applications and Reviews), 38(5):649–659.
Publicado
01/09/2026
WENDLING, Pedro Henrique Ferreira; MASCARENHAS, Dalbert Matos. WebTrap: Uma ferramenta de detecção de ataques em requisições HTTP utilizando Aprendizado de Máquina. In: SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2026 . p. 1308-1323. DOI: https://doi.org/10.5753/sbseg.2026.27112.