Impact of class distribution on the detection of slow HTTP DoS attacks using Big Data

被引:0
|
作者
Chad L. Calvert
Taghi M. Khoshgoftaar
机构
[1] Florida Atlantic University,
来源
关键词
Class imbalance; Slow HTTP DoS; Class imbalance; Big Data;
D O I
暂无
中图分类号
学科分类号
摘要
The integrity of modern network communications is constantly being challenged by more sophisticated intrusion techniques. Attackers are consistently shifting to stealthier and more complex forms of attacks in an attempt to bypass known mitigation strategies. In recent years, attackers have begun to focus their attack efforts on the application layer, allowing them to produce attacks that can exploit known issues within specific application protocols. Slow HTTP Denial of Service attacks are one such attack variant, which targets the HTTP protocol and can imitate legitimate user traffic in order to deny resources from a service. Successful mitigation of this attack type requires network analysts to evaluate large quantities of network traffic to identify and block intrusive traffic. The issue, is that the number of legitimate traffic instances can far outnumber the amount of attack instances, making detection problematic. Machine learning techniques can be used to aid in detection, but the large level of imbalance between normal (majority) and attack (minority) instances can lead to inaccurate detection results. In this work, we evaluate the use of data sampling to produce varying class distributions in order to counteract the effects of severely imbalanced Slow HTTP DoS big datasets. We also detail our process for collecting real-world representative Slow HTTP DoS attack traffic from a live network environment to create our datasets. Five class distributions are generated to evaluate the Slow HTTP DoS detection performance of eight machine learning techniques. Our results show that the optimal learner and class distribution combination is that of Random Forest with a 65:35 distribution ratio, obtaining an AUC value of 0.99904. Further, we determine through the use of significance testing, that the use of sampling techniques can significantly increase learner performance when detecting Slow HTTP DoS attack traffic.
引用
收藏
相关论文
共 50 条
  • [1] Impact of class distribution on the detection of slow HTTP DoS attacks using Big Data
    Calvert, Chad L.
    Khoshgoftaar, Taghi M.
    JOURNAL OF BIG DATA, 2019, 6 (01)
  • [2] Analysis of the Impact of the Slow HTTP DOS and DDOS Attacks on the Cloud Environment
    Yevsieieva, Oksana
    Helalat, Seyed Milad
    2017 4TH INTERNATIONAL SCIENTIFIC-PRACTICAL CONFERENCE PROBLEMS OF INFOCOMMUNICATIONS-SCIENCE AND TECHNOLOGY (PIC S&T), 2017, : 519 - 523
  • [3] WiP: Characterizing the Impact of Multiplexed DoS Attacks on HTTP and Detection
    Sood, Shaurya
    Palod, Pritesh
    Hubballi, Neminath
    INFORMATION SYSTEMS SECURITY, ICISS 2022, 2022, 13784 : 260 - 271
  • [4] How Secure are Web Servers? An Empirical Study of Slow HTTP DoS Attacks and Detection
    Tripathi, Nikhil
    Hubballi, Neminath
    Singh, Yogendra
    PROCEEDINGS OF 2016 11TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY, (ARES 2016), 2016, : 454 - 463
  • [5] Credibility-Based Countermeasure Against Slow HTTP DoS Attacks by Using SDN
    Wang, You-Chiun
    Ye, Ren-Xuan
    2021 IEEE 11TH ANNUAL COMPUTING AND COMMUNICATION WORKSHOP AND CONFERENCE (CCWC), 2021, : 890 - 895
  • [6] HTTP Low and Slow DoS Attack Detection using LSTM based deep learning
    Gogoi, Bronjon
    Ahmed, Tasiruddin
    2022 IEEE 19TH INDIA COUNCIL INTERNATIONAL CONFERENCE, INDICON, 2022,
  • [7] A deep learning based HTTP slow DoS classification approach using flow data
    Muraleedharan, N.
    Janet, B.
    ICT EXPRESS, 2021, 7 (02): : 210 - 214
  • [8] Delays Have Dangerous Ends: Slow HTTP/2 DoS Attacks Into the Wild and Their Real-Time Detection Using Event Sequence Analysis
    Tripathi, Nikhil
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2024, 21 (03) : 1244 - 1256
  • [9] THE SLOW HTTP DDOS ATTACKS: DETECTION, MITIGATION AND PREVENTION IN THE CLOUD ENVIRONMENT
    Dhanapal, A.
    Nithyanandam, P.
    SCALABLE COMPUTING-PRACTICE AND EXPERIENCE, 2019, 20 (04): : 669 - 685
  • [10] Slow rate denial of service attacks against HTTP/2 and detection
    Tripathi, Nikhil
    Hubballi, Neminath
    COMPUTERS & SECURITY, 2018, 72 : 255 - 272