Author/Authors :
Amirshahi, Bita Department of Computer Engineering - Payam Noor University , Ahangari, Ali Department of Computer Engineering - Payam Noor University
Abstract :
Today, botnets have become a
serious threat to enterprise networks. By creation
of network of bots, they launch several attacks,
distributed denial of service attacks (DDoS)
on networks is a sample of such attacks. Such
attacks with the occupation of system resources,
have proven to be an effective method of denying
network services. Botnets that launch HTTP
packet flood attacks against Web servers are one
of the newest and most troublesome threats in
networks. In this paper, we present a system called
HF-Blocker that detects and prevents the HTTP
flood attacks. The proposed system, by checking
at the HTTP request in three stages, a Java-based
test, check cookies and then check the user agent,
detects legitimate source of communication from
malicios source, such as botnets. If it is proved the
source of connection to be bot, HF-Blocker blocks
the request and denies it to access to resources of
the web server and thereby prevent a denial of
service attack. Performance analysis showed that
HF-Blocker, detects and prevents the HTTP-based
attacks of botnets with high probability.
Keywords :
HTTP Flood , HTTP , DDoS attacks , web servers , botnet