{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,10]],"date-time":"2026-07-10T02:07:24Z","timestamp":1783649244823,"version":"3.55.0"},"reference-count":47,"publisher":"MDPI AG","issue":"10","license":[{"start":{"date-parts":[[2022,10,13]],"date-time":"2022-10-13T00:00:00Z","timestamp":1665619200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"Joint Fund of the Chinese Ministry of Education and China Mobile Communications Group Co.,Ltd","award":["MCM20200103"],"award-info":[{"award-number":["MCM20200103"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Symmetry"],"abstract":"<jats:p>The exponential expansion of Internet interconnectivity has led to a dramatic increase in cyber-attack alerts, which contain a considerable proportion of false positives. The overwhelming number of false positives cause tremendous resource consumption and delay responses to the really severe incidents, namely, alert fatigue. To cope with the challenge from alert fatigue, we focus on enhancing the capability of detectors to reduce the generation of false alerts from the detection perspective. The core idea of our work is to train a machine-learning-based detector to grasp the empirical intelligence of security analysts to estimate the feasibility of an incoming HTTP request to cause substantial threats, and integrate the estimation into the detection stage to reduce false alarms. To this end, we innovatively introduce the concept of attack feasibility to characterize the composition rationality of an inbound HTTP request as a feasible attack under static scrutinization. First, we adopt a fast request-reorganization algorithm to transform an HTTP request into the form of interface:payload pair for further alignment of structural components which can reveal the processing logic of the target program. Then, we build a dual-channel attention-based circulant convolution neural network (DualAC2NN) to integrate the attack feasibility estimation into the alert decision, by comprehensively considering the interface sensitivity, payload maliciousness, and their bipartite compatibility. Experiments on a real-world dataset show that the proposed method significantly reduces invalid alerts by around 86.37% and over 61.64% compared to a rule-based commercial WAF and several state-of-the-art methods, along with retaining a detection rate at 97.89% and a lower time overhead, which indicates that our approach can effectively mitigate alert fatigue from the detection perspective.<\/jats:p>","DOI":"10.3390\/sym14102138","type":"journal-article","created":{"date-parts":[[2022,10,14]],"date-time":"2022-10-14T01:44:13Z","timestamp":1665711853000},"page":"2138","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":11,"title":["DualAC2NN: Revisiting and Alleviating Alert Fatigue from the Detection Perspective"],"prefix":"10.3390","volume":"14","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7063-9182","authenticated-orcid":false,"given":"Gang","family":"Yang","sequence":"first","affiliation":[{"name":"College of Electronic Science and Technology, National University of Defense Technology, Changsha 410073, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Chaojing","family":"Tang","sequence":"additional","affiliation":[{"name":"College of Electronic Science and Technology, National University of Defense Technology, Changsha 410073, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xingtong","family":"Liu","sequence":"additional","affiliation":[{"name":"College of Electronic Science and Technology, National University of Defense Technology, Changsha 410073, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2022,10,13]]},"reference":[{"key":"ref_1","unstructured":"Libinjection (2022, June 10). From SQLI to XSS v2. Available online: https:\/\/www.client9.com\/libinjection-from-sqli-to-xss-v2."},{"key":"ref_2","unstructured":"ModSecurity (2022, June 10). Open Source Web Application Firewall. Available online: http:\/\/www.modsecurity.org\/."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"864","DOI":"10.1016\/j.comnet.2008.11.011","article-title":"McPAD: A multiple classifier system for accurate payload-based anomaly detection","volume":"53","author":"Perdisci","year":"2009","journal-title":"Comput. Netw."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"330","DOI":"10.1016\/j.eswa.2016.07.036","article-title":"OCPAD: One class Naive Bayes classifier for payload based anomaly detection","volume":"64","author":"Swarnkar","year":"2016","journal-title":"Expert Syst. Appl."},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Cheng, Z., Cui, B., and Fu, J. (2020, January 26\u201327). A novel web anomaly detection approach based on semantic structure. Proceedings of the International Symposium on Security and Privacy in Social Networks and Big Data, Tianjin, China.","DOI":"10.1007\/978-981-15-9031-3_2"},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Wang, J., Zhou, Z., and Chen, J. (2018, January 26\u201328). Evaluating CNN and LSTM for web attack detection. Proceedings of the 2018 10th International Conference on Machine Learning and Computing, Macau, China.","DOI":"10.1145\/3195106.3195107"},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"818","DOI":"10.1002\/sec.613","article-title":"Semantic aware attribution analysis of remote exploits","volume":"6","author":"Kong","year":"2013","journal-title":"Secur. Commun. Netw."},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Hindy, H., Atkinson, R., Tachtatzis, C., Colin, J.N., Bayne, E., and Bellekens, X. (2020). Utilising deep learning techniques for effective zero-day attack detection. Electronics, 9.","DOI":"10.3390\/electronics9101684"},{"key":"ref_9","unstructured":"Wang, K., and Stolfo, S.J. Anomalous payload-based network intrusion detection. Proceedings of the International Workshop on Recent Advances in Intrusion Detection."},{"key":"ref_10","unstructured":"Enterprisetalk (2022, June 10). Cybersecurity Professionals Face Alert Fatigue. Available online: https:\/\/enterprisetalk.com\/featured\/cybersecurity-professionals-face-alert-fatigue."},{"key":"ref_11","unstructured":"Mcafee (2022, June 10). Security Professionals Ignore Alerts. Available online: https:\/\/www.mcafee.com\/blogs\/enterprise\/cloud-security\/alert-fatigue-31-9-of-it-security-professionals-ignore-alerts\/."},{"key":"ref_12","unstructured":"Fireeye (2022, June 10). How Many Alerts Is Too Many to Handle?. Available online: https:\/\/www2.fireeye.com\/StopTheNoise-IDC-Numbers-Game-Special-Report.html."},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Zengy, J., Wang, X., Liu, J., Chen, Y., Liang, Z., Chua, T.S., and Chua, Z.L. (2022, January 22\u201326). Shadewatcher: Recommendation-guided cyber threat analysis using system audit records. Proceedings of the 2022 IEEE Symposium on Security and Privacy (SP), Francisco, CA, USA.","DOI":"10.1109\/SP46214.2022.9833669"},{"key":"ref_14","unstructured":"Bloom (2022, June 10). Target Missed Warnings in Epic Hack of Credit Card Data. Available online: https:\/\/bloom.bg\/2KjElxM."},{"key":"ref_15","unstructured":"Barre, M., Gehani, A., and Yegneswaran, V. (2019, January 3). Mining data provenance to detect advanced persistent threats. Proceedings of the 11th International Workshop on Theory and Practice of Provenance (TaPP 2019), Philadelphia, PA, USA."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"102282","DOI":"10.1016\/j.cose.2021.102282","article-title":"Threat detection and investigation with system-level provenance graphs: A survey","volume":"106","author":"Li","year":"2021","journal-title":"Comput. Secur."},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Hassan, W.U., Guo, S., Li, D., Chen, Z., Jee, K., Li, Z., and Bates, A. (2019, January 24\u201327). Nodoze: Combatting threat alert fatigue with automated provenance triage. Proceedings of the Network and Distributed Systems Security Symposium, San Diego, CA, USA.","DOI":"10.14722\/ndss.2019.23349"},{"key":"ref_18","unstructured":"Imperva (2022, June 10). Attack Analysis. Available online: https:\/\/www.imperva.com\/blog\/avoid-alert-fatigue-how-to-automatically-get-rid-of-waf-false-positive\/."},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Yoshimura, N., Kuzuno, H., Shiraishi, Y., and Morii, M. (2022). DOC-IDS: A Deep Learning-Based Method for Feature Extraction and Anomaly Detection in Network Traffic. Sensors, 22.","DOI":"10.3390\/s22124405"},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"5450","DOI":"10.1109\/TIP.2019.2917862","article-title":"Learning deep features for one-class classification","volume":"28","author":"Perera","year":"2019","journal-title":"IEEE Trans. Image Process."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Sarhan, M., Layeghy, S., Moustafa, N., Gallagher, M., and Portmann, M. (2022). Feature extraction for machine learning-based intrusion detection in IoT networks. Digit. Commun. Netw.","DOI":"10.21203\/rs.3.rs-2035633\/v1"},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"106887","DOI":"10.1016\/j.knosys.2021.106887","article-title":"Network intrusion detection with a novel hierarchy of distances between embeddings of hash IP addresses","volume":"219","author":"Carro","year":"2021","journal-title":"Knowl.-Based Syst."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"200","DOI":"10.1016\/j.inffus.2021.09.014","article-title":"Supervised contrastive learning over prototype-label embeddings for network intrusion detection","volume":"79","author":"Arribas","year":"2022","journal-title":"Inf. Fusion"},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Pontiki, M., Galanis, D., Papageorgiou, H., Androutsopoulos, I., Manandhar, S., Al-Smadi, M., Al-Ayyoub, M., Zhao, Y., Qin, B., and De Clercq, O. (2016, January 16\u201317). Semeval-2016 task 5: Aspect based sentiment analysis. Proceedings of the International Workshop on Semantic Evaluation, San Diego, CA, USA.","DOI":"10.18653\/v1\/S16-1002"},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"272","DOI":"10.1016\/j.eswa.2018.10.003","article-title":"Deep learning for aspect-based sentiment analysis: A comparative review","volume":"118","author":"Do","year":"2019","journal-title":"Expert Syst. Appl."},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Wu, A., and Han, Y. (2018, January 13\u201319). Multi-modal Circulant Fusion for Video-to-Language and Backward. Proceedings of the IJCAI, Stockholm, Sweden.","DOI":"10.24963\/ijcai.2018\/143"},{"key":"ref_27","unstructured":"RPC-2616 (2022, June 10). Hypertext Transfer Protocol\u2013HTTP\/1.1. Available online: https:\/\/datatracker.ietf.org\/doc\/rfc2616."},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Yu, Y., Yan, H., Ma, Y., Zhou, H., and Guan, H. (2020). DeepHTTP: Anomalous HTTP Traffic Detection and Malicious Pattern Mining Based on Deep Learning. Proceedings of the China Cyber Security Annual Conference, Springer.","DOI":"10.1007\/978-981-33-4922-3_11"},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Yu, L., Chen, L., Dong, J., Li, M., Liu, L., Zhao, B., and Zhang, C. (2020, January 13\u201317). Detecting malicious web requests using an enhanced textcnn. Proceedings of the 2020 IEEE 44th Annual Computers, Software, and Applications Conference (COMPSAC), Madrid, Spain.","DOI":"10.1109\/COMPSAC48688.2020.0-167"},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"1963","DOI":"10.1109\/TII.2019.2938778","article-title":"A distributed deep learning system for web attack detection on edge devices","volume":"16","author":"Tian","year":"2019","journal-title":"IEEE Trans. Ind. Inform."},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"6661124","DOI":"10.1155\/2021\/6661124","article-title":"An Improved Feature Extraction Approach for Web Anomaly Detection Based on Semantic Structure","volume":"2021","author":"Cheng","year":"2021","journal-title":"Secur. Commun. Netw."},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Liu, T., Qi, Y., Shi, L., and Yan, J. (2019, January 10\u201316). Locate-Then-Detect: Real-time Web Attack Detection via Attention-based Deep Neural Networks. Proceedings of the IJCAI, Macao, China.","DOI":"10.24963\/ijcai.2019\/656"},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"811","DOI":"10.1016\/j.comnet.2012.10.002","article-title":"Repids: A multi tier real-time payload-based intrusion detection system","volume":"57","author":"Jamdagni","year":"2013","journal-title":"Comput. Netw."},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"102372","DOI":"10.1016\/j.cose.2021.102372","article-title":"Phishing websites detection via CNN and multi-head self-attention on imbalanced datasets","volume":"108","author":"Xiao","year":"2021","journal-title":"Comput. Secur."},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Kazato, Y., Nakagawa, Y., and Nakatani, Y. (2020, January 10\u201313). Improving maliciousness estimation of indicator of compromise using graph convolutional networks. Proceedings of the 2020 IEEE 17th Annual Consumer Communications & Networking Conference (CCNC), Las Vegas, NV, USA.","DOI":"10.1109\/CCNC46108.2020.9045113"},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"39","DOI":"10.3389\/fpsyg.2018.00039","article-title":"Characterizing and measuring maliciousness for cybersecurity risk assessment","volume":"9","author":"King","year":"2018","journal-title":"Front. Psychol."},{"key":"ref_37","unstructured":"(2022, June 10). Understanding SOAP Security. Available online: https:\/\/blog.dreamfactory.com\/understanding-soap-security\/."},{"key":"ref_38","unstructured":"(2022, June 10). CVE-2020-14472 Detail, Available online: https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2020-14472."},{"key":"ref_39","unstructured":"(2022, June 10). CVE-2020-8515 Detail, Available online: https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2020-8515."},{"key":"ref_40","unstructured":"Apache Struts (2022, June 10). List of Security Vulnerabilities. Available online: https:\/\/www.cvedetails.com\/vulnerability-list\/vendor_id-45\/product_id-6117\/Apache-Struts.html."},{"key":"ref_41","doi-asserted-by":"crossref","first-page":"1767","DOI":"10.1016\/j.infsof.2013.04.002","article-title":"Predicting SQL injection and cross site scripting vulnerabilities through mining input sanitization patterns","volume":"55","author":"Shar","year":"2013","journal-title":"Inf. Softw. Technol."},{"key":"ref_42","doi-asserted-by":"crossref","first-page":"688","DOI":"10.1109\/TDSC.2014.2373377","article-title":"Web application vulnerability prediction using hybrid program analysis and machine learning","volume":"12","author":"Shar","year":"2014","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"ref_43","unstructured":"Drdobbs (2022, June 10). A New Algorithm for Data Compression. Available online: https:\/\/www.drdobbs.com\/a-new-algorithm-for-data-compression\/184402829."},{"key":"ref_44","doi-asserted-by":"crossref","unstructured":"Pennington, J., Socher, R., and Manning, C.D. (2014, January 25\u201329). Glove: Global vectors for word representation. Proceedings of the 2014 Conference on Empirical Methods in Natural Language Processing (EMNLP), Doha, Qatar.","DOI":"10.3115\/v1\/D14-1162"},{"key":"ref_45","doi-asserted-by":"crossref","unstructured":"Zhao, Z., and Wu, Y. (2016, January 8\u201312). Attention-Based Convolutional Neural Networks for Sentence Classification. Proceedings of the Interspeech, San Francisco, CA, USA.","DOI":"10.21437\/Interspeech.2016-354"},{"key":"ref_46","unstructured":"Chen, Y. (2015). Convolutional Neural Network for Sentence Classification. [Master\u2019s Thesis, University of Waterloo]."},{"key":"ref_47","unstructured":"Mikolov, T., Chen, K., Corrado, G., and Dean, J. (2013). Efficient estimation of word representations in vector space. arXiv."}],"container-title":["Symmetry"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2073-8994\/14\/10\/2138\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T00:53:26Z","timestamp":1760144006000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2073-8994\/14\/10\/2138"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,10,13]]},"references-count":47,"journal-issue":{"issue":"10","published-online":{"date-parts":[[2022,10]]}},"alternative-id":["sym14102138"],"URL":"https:\/\/doi.org\/10.3390\/sym14102138","relation":{},"ISSN":["2073-8994"],"issn-type":[{"value":"2073-8994","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,10,13]]}}}