Impact of class distribution on the detection of slow HTTP DoS attacks using Big Data

被引:0
|
作者
Chad L. Calvert
Taghi M. Khoshgoftaar
机构
[1] Florida Atlantic University,
来源
关键词
Class imbalance; Slow HTTP DoS; Class imbalance; Big Data;
D O I
暂无
中图分类号
学科分类号
摘要
The integrity of modern network communications is constantly being challenged by more sophisticated intrusion techniques. Attackers are consistently shifting to stealthier and more complex forms of attacks in an attempt to bypass known mitigation strategies. In recent years, attackers have begun to focus their attack efforts on the application layer, allowing them to produce attacks that can exploit known issues within specific application protocols. Slow HTTP Denial of Service attacks are one such attack variant, which targets the HTTP protocol and can imitate legitimate user traffic in order to deny resources from a service. Successful mitigation of this attack type requires network analysts to evaluate large quantities of network traffic to identify and block intrusive traffic. The issue, is that the number of legitimate traffic instances can far outnumber the amount of attack instances, making detection problematic. Machine learning techniques can be used to aid in detection, but the large level of imbalance between normal (majority) and attack (minority) instances can lead to inaccurate detection results. In this work, we evaluate the use of data sampling to produce varying class distributions in order to counteract the effects of severely imbalanced Slow HTTP DoS big datasets. We also detail our process for collecting real-world representative Slow HTTP DoS attack traffic from a live network environment to create our datasets. Five class distributions are generated to evaluate the Slow HTTP DoS detection performance of eight machine learning techniques. Our results show that the optimal learner and class distribution combination is that of Random Forest with a 65:35 distribution ratio, obtaining an AUC value of 0.99904. Further, we determine through the use of significance testing, that the use of sampling techniques can significantly increase learner performance when detecting Slow HTTP DoS attack traffic.
引用
收藏
相关论文
共 50 条
  • [31] Denial of Service (DoS) Attacks Detection in MANETs Using Bayesian Classifiers
    Rmayti, M.
    Begriche, Y.
    Khatoun, R.
    Khoukhi, L.
    Gaiti, D.
    2014 IEEE 21ST SYMPOSIUM ON COMMUNICATIONS AND VEHICULAR TECHNOLOGY IN THE BENELUX (SCVT), 2014, : 7 - 12
  • [32] Analysis and Detection of DoS Attacks in Cloud Computing by Using QSE Algorithm
    Reddy, Pallavali Radha Krishna
    Bouzefrane, Samia
    2014 IEEE INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE COMPUTING AND COMMUNICATIONS, 2014 IEEE 6TH INTL SYMP ON CYBERSPACE SAFETY AND SECURITY, 2014 IEEE 11TH INTL CONF ON EMBEDDED SOFTWARE AND SYST (HPCC,CSS,ICESS), 2014, : 1089 - 1096
  • [33] The detection of low-rate DoS attacks using the SADBSCAN algorithm
    Tang, Dan
    Zhang, Siqi
    Chen, Jingwen
    Wang, Xiyin
    INFORMATION SCIENCES, 2021, 565 : 229 - 247
  • [34] A System Architecture for the Detection of Insider Attacks in Big Data Systems
    Aditham, Santosh
    Ranganathan, Nagarajan
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2018, 15 (06) : 974 - 987
  • [35] Early Detection of DOS Attacks in VANET Using Attacked Packet Detection Algorithm (APDA)
    RoselinMary, S.
    Maheshwari, M.
    Thamaraiselvan, M.
    2013 INTERNATIONAL CONFERENCE ON INFORMATION COMMUNICATION AND EMBEDDED SYSTEMS (ICICES), 2013, : 237 - 240
  • [36] Detection of low intensity dos attacks using fuzzy based intrusion detection system
    Baig, Habibullah
    Kamran, Farrukh
    ICECE 2006: PROCEEDINGS OF THE 4TH INTERNATIONAL CONFERENCE ON ELECTRICAL AND COMPUTER ENGINEERING, 2006, : 591 - 594
  • [37] Medicare Fraud Detection using Random Forest with Class Imbalanced Big Data
    Bauder, Richard A.
    Khoshgoftaar, Taghi M.
    2018 IEEE INTERNATIONAL CONFERENCE ON INFORMATION REUSE AND INTEGRATION (IRI), 2018, : 80 - 87
  • [38] HeteMSD: A Big Data Analytics Framework for Targeted Cyber-Attacks Detection Using Heterogeneous Multisource Data
    Ju, Ankang
    Guo, Yuanbo
    Ye, Ziwei
    Li, Tao
    Ma, Jing
    SECURITY AND COMMUNICATION NETWORKS, 2019, 2019
  • [39] The effects of varying class distribution on learner behavior for medicare fraud detection with imbalanced big data
    Bauder, Richard A.
    Khoshgoftaar, Taghi M.
    HEALTH INFORMATION SCIENCE AND SYSTEMS, 2018, 6
  • [40] Detection and reconstruction of measurements against false data injection and DoS attacks in distribution system state estimation: A deep learning approach
    Raghuvamsi, Y.
    Teeparthi, Kiran
    MEASUREMENT, 2023, 210