HTTP-sCAN: Detecting HTTP-Flooding Attack by Modeling Multi-Features of Web Browsing Behavior from Noisy Web-Logs

被引:8
|
作者
Wang Jin [1 ,3 ]
Zhang Min [1 ]
Yang Xiaolong [1 ]
Long Keping [1 ]
Xu Me [2 ]
机构
[1] Univ Sci & Technol Beijing, Sch Comp & Commun Engn, Beijing 100083, Peoples R China
[2] Univ Elect Sci & Technol China, Sch Commun & Informat Engineer, Res Ctr Opt Internet & Mobile Informat Network, Chengdu 611731, Peoples R China
[3] Chengdu Univ, Network Ctr, Chengdu 610106, Sichuan Provinc, Peoples R China
基金
中国国家自然科学基金;
关键词
IP network; DDoS; relative entropy; cluster algorithm;
D O I
10.1109/CC.2015.7084407
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
HTTP-flooding attack disables the victimized web server by sending a large number of HTTP Get requests. Recent research tends to detect HTTP-flooding with the anomaly-based approaches, which detect the HTTP-flooding by modeling the behavior of normal web surfers. However, most of the existing anomaly-based detection approaches usually cannot filter the web-crawling traces from unknown searching bots mixed in normal web browsing logs. These web-crawling traces can bias the base-line profile of anomaly-based schemes in their training phase, and further degrade their detection performance. This paper proposes a novel web-crawling traces-tolerated method to build baseline profile, and designs a new anomaly-based HTTP-flooding detection scheme (abbr. HTTP-sCAN). The simulation results show that HTTP-sCAN is immune to the interferences of unknown web-crawling traces, and can detect all HTTP-flooding attacks.
引用
收藏
页码:118 / 128
页数:11
相关论文
共 3 条
  • [1] HTTP-sCAN:Detecting HTTP-Flooding Attack by Modeling Multi-Features of Web Browsing Behavior from Noisy Web-Logs
    WANG Jin
    ZHANG Min
    YANG Xiaolong
    LONG Keping
    XU Jie
    中国通信, 2015, 12 (02) : 118 - 128
  • [2] HTTP-sCAN:Detecting HTTP-Flooding Attack by Modeling Multi-Features of Web Browsing Behavior from Noisy Web-Logs
    WANG Jin
    ZHANG Min
    YANG Xiaolong
    LONG Keping
    XU Jie
    China Communications, 2015, (02) : 118 - 128
  • [3] HTTP-sCAN: detecting HTTP-flooding attaCk by modeling multi-feAtures of web browsing behavior from Noisy dataset
    Wang, Jin
    Zhang, Min
    Yang, Xiaolong
    Long, Keping
    Zhou, Chimin
    2013 19TH ASIA-PACIFIC CONFERENCE ON COMMUNICATIONS (APCC): SMART COMMUNICATIONS TO ENHANCE THE QUALITY OF LIFE, 2013, : 677 - 682