Monitoring the Application-Layer DDoS Attacks for Popular Websites

被引:153
作者
Xie, Yi [1 ]
Yu, Shun-Zheng [1 ]
机构
[1] Sun Yat Sen Univ, Dept Elect & Commun Engn, Sch Informat Sci & Technol, Guangzhou 510275, Guangdong, Peoples R China
基金
国家高技术研究发展计划(863计划);
关键词
Application-layer; distributed denial of service (DDoS); popular Website;
D O I
10.1109/TNET.2008.925628
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Distributed denial of service (DDoS) attack is a continuous critical threat to the Internet. Derived from the low layers, new application-layer-based DDoS attacks utilizing legitimate HTTP requests to overwhelm victim resources are more undetectable. The case may be more serious when such attacks mimic or occur during the flash crowd event of a popular Website. Focusing on the detection for such new DDoS attacks, a scheme based on document popularity is introduced. An Access Matrix is defined to capture the spatial-temporal patterns of a normal flash crowd. Principal component analysis and independent component analysis are applied to abstract the multidimensional Access Matrix. A novel anomaly detector based on hidden semi-Markov model is proposed to describe the dynamics of Access Matrix and to detect the attacks. The entropy of document popularity fitting to the model is used to detect the potential application-layer DDoS attacks. Numerical results based on real Web traffic data are presented to demonstrate the effectiveness of the proposed method.
引用
收藏
页码:15 / 25
页数:11
相关论文
共 30 条
[1]  
ARI I, 2004, UCSCCRL0315
[2]   User centric walk:: An integrated approach for modeling the browsing behavior of users on the Web [J].
Bürklen, S ;
Marrón, PJ ;
Fritsch, S ;
Rothermel, K .
38TH ANNUAL SIMULATION SYMPOSIUM, PROCEEDINGS, 2005, :149-159
[3]  
Cabrera J. B. D., 2001, 2001 IEEE/IFIP International Symposium on Integrated Network Management Proceedings. Integrated Network Management VII. Integrated Management Strategies for the New Millennium (Cat. No.01EX470), P609, DOI 10.1109/INM.2001.918069
[4]  
Cao J, 2004, IEEE INFOCOM SER, P1546
[5]  
*CERT, 2004, INC NOT IN 2004 01 W
[6]  
COOPER AMG, SUMMARY BIOSURVEILLA
[7]  
Hyvarinen A., 1999, Neural Computing Surveys, V2
[8]   Fast and robust fixed-point algorithms for independent component analysis [J].
Hyvärinen, A .
IEEE TRANSACTIONS ON NEURAL NETWORKS, 1999, 10 (03) :626-634
[9]  
Jung J., 2002, Proc. of the International World Wide Web Conference, P252
[10]  
KANDULA S, 2004, TR969 MIT