HTTP-SoLDiER: An HTTP-flooding attack detection scheme with the large deviation principle

被引:0
|
作者
Jin Wang
XiaoLong Yang
Min Zhang
KePing Long
Jie Xu
机构
[1] University of Electronic Science and Technology of China,Research Center for Optical Internet and Mobile Information Network
[2] University of Science and Technology Beijing,School of Computer and Communications Engineering
[3] Network Center of Chengdu University,undefined
来源
关键词
IP network; distributed denial of service (DDoS); the large deviation principle; exponential weight moving average; Ns-3; 102301;
D O I
暂无
中图分类号
学科分类号
摘要
HTTP-flooding attack is a much stealthier distributed denial of service (DDoS) attack, challenging the survivability of the web services seriously. Observing the web access behavior, we find that the surfing preference of normal users is much more consistent with the webpage popularity than that of malicious users. Based on this observation, this paper proposes a novel detection scheme for HTTP-flooding (HTTP-SoLDiER). Specifically, HTTP-SoLDiER first quantifies the consistency between web users surfing preference and the webpage popularity with large-deviation principle. Then HTTP-SoLDiER distinguishes the malicious users from normal ones according to the large-deviation probability. In practice, the webpage popularity plays a key role in attack detection of HTTP-SoLDiER. Due to the never-ending updating of the webpage content and the disturbance induced by attackers, the webpage popularity often varies over time. Thus, it is critical for HTTP-SoLDiER to dynamically update the webpage popularity. We design a reversible exponentially weighted moving average (EWMA) algorithm to solve the problem. Finally, we evaluate the effectiveness of this scheme in terms of true positive (TP) and false positive (FP) probabilities with NS-3 simulations. The simulation results show that HTTP-SoLDiER can detect all random HTTP-flooding attackers and most of the perfect-knowledge HTTP-flooding attackers at little false positive.
引用
收藏
页码:1 / 15
页数:14
相关论文
共 50 条
  • [1] HTTP-SoLDiER: An HTTP-flooding attack detection scheme with the large deviation principle
    Wang Jin
    Yang XiaoLong
    Zhang Min
    Long KePing
    Xu Jie
    [J]. SCIENCE CHINA-INFORMATION SCIENCES, 2014, 57 (10) : 1 - 15
  • [2] HTTP-SoLDiER: An HTTP-flooding attack detection scheme with the large deviation principle
    WANG Jin
    YANG XiaoLong
    ZHANG Min
    LONG KePing
    XU Jie
    [J]. Science China(Information Sciences), 2014, 57 (10) : 5 - 19
  • [3] HTTP-sCAN: detecting HTTP-flooding attaCk by modeling multi-feAtures of web browsing behavior from Noisy dataset
    Wang, Jin
    Zhang, Min
    Yang, Xiaolong
    Long, Keping
    Zhou, Chimin
    [J]. 2013 19TH ASIA-PACIFIC CONFERENCE ON COMMUNICATIONS (APCC): SMART COMMUNICATIONS TO ENHANCE THE QUALITY OF LIFE, 2013, : 677 - 682
  • [4] HTTP-sCAN:Detecting HTTP-Flooding Attack by Modeling Multi-Features of Web Browsing Behavior from Noisy Web-Logs
    WANG Jin
    ZHANG Min
    YANG Xiaolong
    LONG Keping
    XU Jie
    [J]. 中国通信, 2015, 12 (02) : 118 - 128
  • [5] HTTP-sCAN: Detecting HTTP-Flooding Attack by Modeling Multi-Features of Web Browsing Behavior from Noisy Web-Logs
    Wang Jin
    Zhang Min
    Yang Xiaolong
    Long Keping
    Xu Me
    [J]. CHINA COMMUNICATIONS, 2015, 12 (02) : 118 - 128
  • [6] HTTP-sCAN:Detecting HTTP-Flooding Attack by Modeling Multi-Features of Web Browsing Behavior from Noisy Web-Logs
    WANG Jin
    ZHANG Min
    YANG Xiaolong
    LONG Keping
    XU Jie
    [J]. China Communications, 2015, (02) : 118 - 128
  • [7] Http-flood DDoS detection scheme based on large deviation and performance analysis
    [J]. Yang, X.-L. (yxl@uestc.edu.cn), 1600, Chinese Academy of Sciences (23):
  • [8] The HTTP Flooding Attack Detection to Secure and Safeguard Online Applications in the Cloud
    Dhanapal, A.
    Nithyanandam, P.
    [J]. INTERNATIONAL JOURNAL OF INFORMATION SYSTEM MODELING AND DESIGN, 2019, 10 (03) : 41 - 58
  • [9] A Survey on HTTP Flooding-A Distributed Denial of Service Attack
    Khandare, Hrishikesh
    Jain, Saurabh
    Doriya, Rajesh
    [J]. PERVASIVE COMPUTING AND SOCIAL NETWORKING, ICPCSN 2022, 2023, 475 : 39 - 52
  • [10] HTTP Flood Attack Detection using Ontology
    Kshirsagar, Deepak
    Kumar, Sandeep
    [J]. INTERNATIONAL CONFERENCE ON ADVANCES IN INFORMATION COMMUNICATION TECHNOLOGY & COMPUTING, 2016, 2016,