A Selective Defense for Application Layer DDoS Attacks

被引:35
|
作者
Dantas, Yuri G. [1 ]
Nigam, Vivek [1 ]
Fonseca, Iguatemi E. [1 ]
机构
[1] Univ Fed Paraiba, Joao Pessoa, Paraiba, Brazil
来源
2014 IEEE JOINT INTELLIGENCE AND SECURITY INFORMATICS CONFERENCE (JISIC) | 2014年
关键词
D O I
10.1109/JISIC.2014.21
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Distributed Denial of Service (DDoS) attacks remain among the most dangerous and noticeable attacks on the Internet. Differently from previous attacks, many recent DDoS attacks have not been carried out over the network layer, but over the application layer. The main difference is that in the latter, an attacker can target a particular application of the server, while leaving the remaining applications still available, thus generating less traffic and being harder to detect. Such attacks are possible by exploiting application layer protocols used by the target application. This paper proposes a novel defense for Application Layer DDoS attacks (ADDoS) based on the Adaptive Selective Verification (ASV) defense used for mitigating Network Layer DDoS attacks. We formalize our defense mechanism in the computational system Maude and demonstrate by using the statistical model checker PVeStA that it can be used to prevent ADDoS. In particular, we show that even in the presence of a great number of attackers, an application running our defense still has high levels of availability. Moreover, we compare our results to a defense based on traffic monitoring proposed in the literature and show that our defense is more robust and also leads to less traffic.
引用
收藏
页码:75 / 82
页数:8
相关论文
共 50 条
  • [1] Principal Analysis and Defense Technologies of Application Layer DDos Attacks
    Lai Shouliang
    Wang Meiyan
    PROCEEDINGS OF THE 2014 INTERNATIONAL CONFERENCE ON MECHATRONICS, ELECTRONIC, INDUSTRIAL AND CONTROL ENGINEERING, 2014, 5 : 564 - 568
  • [2] Detection and defense of application-layer DDoS attacks in backbone web traffic
    Zhou, Wei
    Jia, Weijia
    Wen, Sheng
    Xiang, Yang
    Zhou, Wanlei
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2014, 38 : 36 - 46
  • [3] SkyShield: A Sketch-Based Defense System Against Application Layer DDoS Attacks
    Wang, Chenxu
    Miu, Tony T. N.
    Luo, Xiapu
    Wang, Jinhe
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2018, 13 (03) : 559 - 573
  • [4] Characterizing the Impacts of Application Layer DDoS Attacks
    Jiang, Muhui
    Wang, Chenxu
    Luo, Xiapu
    Miu, MiuTung
    Chen, Ting
    2017 IEEE 24TH INTERNATIONAL CONFERENCE ON WEB SERVICES (ICWS 2017), 2017, : 500 - 507
  • [5] Tackling Application-layer DDoS Attacks
    Beitollahi, Hakem
    Deconinck, Geert
    ANT 2012 AND MOBIWIS 2012, 2012, 10 : 432 - 441
  • [6] An Effective Approach to Counter Application Layer DDoS Attacks
    Devi, S. Renuka
    Yogesh, P.
    2012 THIRD INTERNATIONAL CONFERENCE ON COMPUTING COMMUNICATION & NETWORKING TECHNOLOGIES (ICCCNT), 2012,
  • [7] A Lightweight Mechanism to Mitigate Application Layer DDoS Attacks
    Yu, Jie
    Fang, Chengfang
    Lu, Liming
    Li, Zhoujun
    SCALABLE INFORMATION SYSTEMS, 2009, 18 : 175 - +
  • [8] An Overview on Detection and Prevention of Application Layer DDoS Attacks
    Black, Samuel
    Kim, Yoohwan
    2022 IEEE 12TH ANNUAL COMPUTING AND COMMUNICATION WORKSHOP AND CONFERENCE (CCWC), 2022, : 791 - 800
  • [9] A Novel Approach for Countering Application Layer DDoS Attacks
    Wang, Yadong
    Liu, Lianzhong
    Si, Chengxiang
    Sun, Bo
    2017 IEEE 2ND ADVANCED INFORMATION TECHNOLOGY, ELECTRONIC AND AUTOMATION CONTROL CONFERENCE (IAEAC), 2017, : 1814 - 1817
  • [10] A Survey on DDoS Attacks on Network and Application Layer in IoT
    Pandey, Nimisha
    Mishra, Pramod Kumar
    ADVANCED NETWORK TECHNOLOGIES AND INTELLIGENT COMPUTING, ANTIC 2021, 2022, 1534 : 240 - 250