DDoS Attacks at the Application Layer: Challenges and Research Perspectives for Safeguarding Web Applications

被引:99
作者
Praseed, Amit [1 ]
Thilagam, P. Santhi [1 ]
机构
[1] Natl Inst Technol Karnataka, Dept Comp Sci & Engn, Surathkal 575025, India
关键词
Application layer; DDoS; attacks; defenses; denial of service; taxonomy; detection; Web applications; XQUERY INJECTION; FLOODING ATTACK; DEFENSE; SERVICE; SYSTEM; VULNERABILITIES; DOS;
D O I
10.1109/COMST.2018.2870658
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Distributed denial of service (DDoS) attacks are some of the most devastating attacks against Web applications. A large number of these attacks aim to exhaust the network bandwidth of the server, and are called network layer DDoS attacks. They are volumetric attacks and rely on a large volume of network layer packets to throttle the bandwidth. However, as time passed, network infrastructure became more robust and defenses against network layer attacks also became more advanced. Recently, DDoS attacks have started targeting the application layer. Unlike network layer attacks, these attacks can be carried out with a relatively low attack volume. They also utilize legitimate application layer requests, which makes it difficult for existing defense mechanisms to detect them. These attacks target a wide variety of resources at the application layer and can bring a server down much faster, and with much more stealth, than network layer DDoS attacks. Over the past decade, research on application layer DDoS attacks has focused on a few classes of these attacks. This paper attempts to explore the entire spectrum of application layer DDoS attacks using critical features that aid in understanding how these attacks can be executed. defense mechanisms against the different classes of attacks are also discussed with special emphasis on the features that aid in the detection of different classes of attacks. Such a discussion is expected to help researchers understand why a particular group of features are useful in detecting a particular class of attacks.
引用
收藏
页码:661 / 685
页数:25
相关论文
共 120 条
[1]  
Aamir M., 2013, INTERDISCIP INF SCI, V19, P173, DOI DOI 10.4036/iis.2013.173
[2]  
[Anonymous], DDOS ATT PLAG OL BRA
[3]  
[Anonymous], 2011, PROC INT C ADV COMPU
[4]  
[Anonymous], SCMAGAZINE
[5]  
[Anonymous], 2017, COINDESK
[6]  
[Anonymous], GLOB DDOS THREAT LAN
[7]  
[Anonymous], 2013, THESIS
[8]  
[Anonymous], SINGL REQ HTTP FLOOD
[9]  
[Anonymous], INT TIMES
[10]  
[Anonymous], DNS FLOOD