Title :
Resisting Web Proxy-Based HTTP Attacks by Temporal and Spatial Locality Behavior
Author :
Yi Xie ; Tang, Song ; Xiang, Yingmeng ; Hu, Jiankun
Author_Institution :
Sch. of Inf. Sci. & Technol., Sun YatSen Univ., Guangzhou, China
Abstract :
A novel server-side defense scheme is proposed to resist the Web proxy-based distributed denial of service attack. The approach utilizes the temporal and spatial locality to extract the behavior features of the proxy-to-server traffic, which makes the scheme independent of the traffic intensity and frequently varying Web contents. A nonlinear mapping function is introduced to protect weak signals from the interference of infrequent large values. Then, a new hidden semi-Markov model parameterized by Gaussian-mixture and Gamma distributions is proposed to describe the time-varying traffic behavior of Web proxies. The new method reduces the number of parameters to be estimated, and can characterize the dynamic evolution of the proxy-to-server traffic rather than the static statistics. Two diagnosis approaches at different scales are introduced to meet the requirement of both fine-grained and coarse-grained detection. Soft control is a novel attack response method proposed in this work. It converts a suspicious traffic into a relatively normal one by behavior reshaping rather than rudely discarding. This measure can protect the quality of services of legitimate users. The experiments confirm the effectiveness of the proposed scheme.
Keywords :
Gaussian processes; Web sites; computer network security; content management; gamma distribution; hidden Markov models; hypermedia; interference (signal); network servers; nonlinear functions; quality of service; signal detection; telecommunication traffic; Gaussian mixture model; Web content; Web proxy-based HTTP attack resistance; coarse grained detection; distributed denial of service; dynamic evolution; fine grained detection; gamma distribution; hidden semiMarkov model; interference suppression; nonlinear mapping function; proxy-to-server traffic; quality of service; server side defense scheme; signal protection; spatial locality behavior extraction; static statistics; temporal locality behavior extraction; time-varying traffic behavior; traffic intensity; Computer crime; Educational institutions; Electronic mail; Hidden Markov models; Indexes; Servers; Stochastic processes; Traffic analysis; attack detection; attack response; distributed denial of service attack; traffic modeling;
Journal_Title :
Parallel and Distributed Systems, IEEE Transactions on
DOI :
10.1109/TPDS.2012.232