Publications

View publication

Title Real-Time Anomaly Detection in Web Server Logs Using Machine Learning and Apache Kafka
Authors Valentina Rojas Osorio, Ángel Jiménez-Molina, Cecilia Bastarrica, Felipe Vildoso
Publication date 2026
Abstract Web servers face escalating security threats, with
organizations
experiencing a 75% increase in weekly cyberattacks. Traditional rule-based
intrusion detection systems struggle to identify novel attack patterns,
requiring manual updates for each new threat. The paper evaluates ten
classical and deep-learning algorithms for web-server intrusion detection,
using hyperparameter optimization to find best configurations. The top model
(Support Vector Data Description) achieves an F1 score of 0.975, a 41%
improvement over the commercial Wazuh SIEM. Feature selection shows five
features retain 89% of detection capability while reducing complexity by
88.6%. Generalization to unseen attack types is limited (average performance
drop of 65.8% in Leave-One-Attack-Out tests). We also propose a real-time
anomaly-detection architecture for Apache logs and discuss practical
considerations for deploying ML-based intrusion detection in
production.
Pages 49-56
Conference name International Workshop on Engineering and Cybersecurity of Critical Systems
Publisher ACM Press (New York, NY, USA)
Reference URL View reference page