Research Article

Using XGBoost to Discover Infected Hosts Based on HTTP Traffic

Table 2

HTTP header field information and template comparison.

HTTP header field informationGenerated templates

Accept: Text jsonAccept: Text ∗
Accept-Encoding: Gzip deflateAccept-Encoding: Gzip ∗
Connection: Keep-AliveConnection: ∗
User-Agent: Mozilla 4.0 (compatible; MSIE 6.0; Windows NT 5.1)User-Agent: Mozilla ∗ (compatible; MSIE ∗ Windows NT ∗