Defending HTTP Web Servers against DDoS Attacks through Busy Period-based Attack Flow Detection

被引:5
|
作者
Nam, Seung Yeob [1 ]
Djuraev, Sirojiddin [1 ]
机构
[1] Yeungnam Univ, Dept Informat & Commun Engn, Gyongsan 712749, Gyeongsangbuk D, South Korea
基金
新加坡国家研究基金会;
关键词
denial-of-service (DoS) attacks; application layer DoS attack; admission control; busy period; attack flow detection; Bloom filter; SERVICE ATTACKS;
D O I
10.3837/tiis.2014.07.018
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
We propose a new Distributed Denial of Service (DDoS) defense mechanism that protects http web servers from application-level DDoS attacks based on the two methodologies: whitelist-based admission control and busy period-based attack flow detection. The attack flow detection mechanism detects attach flows based on the symptom or stress at the server, since it is getting more difficult to identify bad flows only based on the incoming traffic patterns. The stress is measured by the time interval during which a given client makes the server busy, referred to as a client-induced server busy period (CSBP). We also need to protect the servers from a sudden surge of attack flows even before the malicious flows are identified by the attack flow detection mechanism. Thus, we use whitelist-based admission control mechanism additionally to control the load on the servers. We evaluate the performance of the proposed scheme via simulation and experiment. The simulation results show that our defense system can mitigate DDoS attacks effectively even under a large number of attack flows, on the order of thousands, and the experiment results show that our defense system deployed on a linux machine is sufficiently lightweight to handle packets arriving at a rate close to the link rate.
引用
收藏
页码:2512 / 2531
页数:20
相关论文
共 4 条
  • [1] Detection of DoS/DDoS attack against HTTP Servers using Naive Bayesian
    Katkar, Vijay
    Zinjade, Amol
    Dalvi, Suyed
    Bafna, Tejal
    Mahajan, Rashmi
    1ST INTERNATIONAL CONFERENCE ON COMPUTING COMMUNICATION CONTROL AND AUTOMATION ICCUBEA 2015, 2015, : 280 - 285
  • [2] Web Proxy based Detection and Protection Mechanisms against Client Based HTTP Attacks
    Pandiaraja, P.
    Manikandan, J.
    2015 INTERNATIONAL CONFERENCED ON CIRCUITS, POWER AND COMPUTING TECHNOLOGIES (ICCPCT-2015), 2015,
  • [3] Enhancing SDN resilience against DDoS attacks through dynamic virtual controller deployment and attack level detection algorithm
    Florance G.
    R J Anandhi
    International Journal of Information Technology, 2024, 16 (7) : 4701 - 4712
  • [4] A Flow-Based Anomaly Detection Approach With Feature Selection Method Against DDoS Attacks in SDNs
    El Sayed, Mahmoud Said
    Le-Khac, Nhien-An
    Azer, Marianne A.
    Jurcut, Anca D.
    IEEE TRANSACTIONS ON COGNITIVE COMMUNICATIONS AND NETWORKING, 2022, 8 (04) : 1862 - 1880