Analysis and detection of application-independent slow Denial of Service cyber attacks

被引:3
作者
Sikora, Marek [1 ]
Fujdiak, Radek [1 ]
Misurec, Jiri [1 ]
机构
[1] Brno Univ Technol, Dept Telecommun, Brno, Czech Republic
来源
2021 IEEE INTERNATIONAL CONFERENCE ON INTELLIGENCE AND SECURITY INFORMATICS (ISI) | 2021年
关键词
slow DoS attacks; Slowcomm; Slow Next; attack generator; intrusion detection system; signatures detection;
D O I
10.1109/ISI53945.2021.9624789
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
This paper investigates current application-independent slow Denial of Service (DoS) attacks. We propose Slowcomm and Slow Next attack models and present an attack simulation tool. We used this tool for vulnerability testing of several Internet services, including Hypertext Transfer Protocol (HTTP), File Transfer Protocol (FTP), and Secure Shell (SSH) servers. We also propose attack signatures and detection methods. We implemented these methods as an Intrusion Detection System (IDS) and tested them in an experimental network. Our testing revealed vulnerabilities in five of the six tested servers that caused the denial of service to legitimate users. Deployment of the proposed attack detector has shown a high detection success. We conclude that there is a need to increase the level of cybersecurity. Internet services are vulnerable to these new DoS attacks. Our analysis can be used for the security development of tested services. Our detector in combination with a network traffic filtering tool can be used to mitigate the attacks and keep the service available to Internet users.
引用
收藏
页码:25 / 30
页数:6
相关论文
共 16 条
[1]  
Aiello Maurizio, 2013, 2013 IEEE Symposium on Computers and Communications (ISCC), P000430, DOI 10.1109/ISCC.2013.6754984
[2]  
Aiello MA., 2014, 200R12013 CNRDT, P1
[3]  
Cambiaso E., 2013, INT J TRUST MANAGEME, V1, P300
[4]   Detection and classification of Slow DoS Attacks targeting network servers [J].
Cambiaso, Enrico ;
Aiello, Maurizio ;
Mongelli, Maurizio ;
Vaccari, Ivan .
15TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY, ARES 2020, 2020,
[5]   Slowcomm: Design, development and performance evaluation of a new slow DoS attack [J].
Cambiaso, Enrico ;
Papaleo, Gianluca ;
Aiello, Maurizio .
JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2017, 35 :23-31
[6]   Designing and Modeling the Slow Next DoS Attack [J].
Cambiaso, Enrico ;
Papaleo, Gianluca ;
Chiola, Giovanni ;
Aiello, Maurizio .
INTERNATIONAL JOINT CONFERENCE: CISIS'15 AND ICEUTE'15, 2015, 369 :249-259
[7]  
Garrett O., 2015, Inside nginx: How we designed for performance & scale
[8]   A survey of distributed denial-of-service attack, prevention, and mitigation techniques [J].
Mahjabin, Tasnuva ;
Xiao, Yang ;
Sun, Guang ;
Jiang, Wangdong .
INTERNATIONAL JOURNAL OF DISTRIBUTED SENSOR NETWORKS, 2017, 13 (12)
[9]  
Sikora M., 2021, P 27 C STUDENT EEICT, P1
[10]   Generator of Slow Denial-of-Service Cyber Attacks [J].
Sikora, Marek ;
Fujdiak, Radek ;
Kuchar, Karel ;
Holasova, Eva ;
Misurec, Jiri .
SENSORS, 2021, 21 (16)