Skip to main content

2024 | OriginalPaper | Buchkapitel

An Accurate and Real-Time Detection Method for Concealed Slow HTTP DoS in Backbone Network

verfasst von : Jinfeng Chen, Hua Wu, Suyue Wang, Guang Cheng, Xiaoyan Hu

Erschienen in: ICT Systems Security and Privacy Protection

Verlag: Springer Nature Switzerland

Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.

search-config
loading …

Abstract

Slow HTTP DoS (SHD) is a type of DoS attack based on HTTP/HTTPS. SHD traffic at the application layer may be encrypted. Besides, the interval between packets can reach tens of seconds or more due to its slow sending rate. Therefore, SHD is concealed for detection. The methods for detecting high-speed DoS are not suitable for detecting the attack, making detection for SHD a challenging problem. Some existing SHD detection methods are complex and computationally intensive, making it hard to meet the demand for real-time in backbone networks. In addition, most of these methods are based on bidirectional traffic and do not consider the asymmetry of routing on the Internet. In this paper, based on the traffic characteristics of the most common types of SHD, we extract several representative features from unidirectional flows. These features can still work well under sampling and asymmetric routing scenarios. We also use Slow HTTP DoS Sketch to record the features quickly and accurately. In experiments that used public backbone datasets as background traffic, the results show that even with a large number of unidirectional flows and a sampling rate of 1/64, our method can still accurately detect SHD traffic within 2 min.

Sie haben noch keine Lizenz? Dann Informieren Sie sich jetzt über unsere Produkte:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Literatur
1.
Zurück zum Zitat Eliyan, L.F., Pietro, R.D.: DoS and DDoS attacks in software defined networks: a survey of existing solutions and research challenges. Future Gener. Comput. Syst. 122, 149–171 (2021)CrossRef Eliyan, L.F., Pietro, R.D.: DoS and DDoS attacks in software defined networks: a survey of existing solutions and research challenges. Future Gener. Comput. Syst. 122, 149–171 (2021)CrossRef
3.
Zurück zum Zitat Tripathi N., Hubballi N., Singh Y.: How secure are web servers? an empirical study of slow HTTP DoS attacks and detection. In: 11th International Conference on Availability, Reliability and Security (ARES), pp. 454–463. IEEE (2016). https://doi.org/10.1109/ARES.2016.20 Tripathi N., Hubballi N., Singh Y.: How secure are web servers? an empirical study of slow HTTP DoS attacks and detection. In: 11th International Conference on Availability, Reliability and Security (ARES), pp. 454–463. IEEE (2016). https://​doi.​org/​10.​1109/​ARES.​2016.​20
4.
Zurück zum Zitat Garcia, N., et al.: Distributed real-time SlowDoS attacks detection over encrypted traffic using Artificial Intelligence. J. Netw. Comput. Appl. 173, 102871 (2021)CrossRef Garcia, N., et al.: Distributed real-time SlowDoS attacks detection over encrypted traffic using Artificial Intelligence. J. Netw. Comput. Appl. 173, 102871 (2021)CrossRef
5.
Zurück zum Zitat Rani, S.J., Ioannou, I., Nagaradjane, P., et al.: Detection of DDoS attacks in D2D communications using machine learning approach. Comput. Commun. 198, 32–51 (2023)CrossRef Rani, S.J., Ioannou, I., Nagaradjane, P., et al.: Detection of DDoS attacks in D2D communications using machine learning approach. Comput. Commun. 198, 32–51 (2023)CrossRef
6.
Zurück zum Zitat Xu, C., Shen, J., Du, X.: Low-rate DoS attack detection method based on hybrid deep neural networks. J. Inf. Secur. Appl. 60, 102879 (2021) Xu, C., Shen, J., Du, X.: Low-rate DoS attack detection method based on hybrid deep neural networks. J. Inf. Secur. Appl. 60, 102879 (2021)
7.
Zurück zum Zitat Jazi, H.H., et al.: Detecting HTTP-based application layer DoS attacks on web servers in the presence of sampling. Comput. Netw. 121, 25–36 (2017)CrossRef Jazi, H.H., et al.: Detecting HTTP-based application layer DoS attacks on web servers in the presence of sampling. Comput. Netw. 121, 25–36 (2017)CrossRef
Metadaten
Titel
An Accurate and Real-Time Detection Method for Concealed Slow HTTP DoS in Backbone Network
verfasst von
Jinfeng Chen
Hua Wu
Suyue Wang
Guang Cheng
Xiaoyan Hu
Copyright-Jahr
2024
DOI
https://doi.org/10.1007/978-3-031-56326-3_15

Premium Partner