DocumentCode :
3073514
Title :
Web DDoS Detection Schemes Based on Measuring User´s Access Behavior with Large Deviation
Author :
Wang, Jin ; Yang, Xiaolong ; Long, Keping
Author_Institution :
Res. Center for Opt. Internet & Mobile Inf. Network, Univ. of Electron. Sci. & Technol. of China, Chengdu, China
fYear :
2011
fDate :
5-9 Dec. 2011
Firstpage :
1
Lastpage :
5
Abstract :
Distributed denial-of-service (DDoS) attack seriously threatens the survivability of web services. It attempts to exhaust a server\´s resources (e.g., I/O bandwidth, CPU, and memory resources) to the extent that no resource is available for requests from legitimate users. Recently, some attackers launch web DDoS attack from the application layer (i.e., web app-DDoS), which can evade most of the existing detection approaches that mainly focused on Bandwidth-Flooding DDoS and TCP SYN-Flooding DDoS. This paper discusses the detection of web app-DDoS, and present two different models to characterize user\´s web access behavior, i.e., click-ratio based model and Markov process based model. With these characterizations as reference, we adopt large deviation theory to estimate the probability that each ongoing user\´s access behavior is "consistent" with the corresponding reference characterization, and propose two different detection schemes, LD-IID and LD-MP, respectively. We also validate our schemes with simulations, and the simulation results show that LD-IID can detect attackers accurately, yet LD-MP has high false negatives.
Keywords :
Markov processes; Web services; computer network security; probability; reliability; transport protocols; LD-IID; LD-MP; Markov process; TCP SYN flooding; Web DDoS detection; Web services; bandwidth flooding; distributed denial of service attack; probability estimation; survivability; users access behavior; Computer crime; Markov processes; Monitoring; Vectors; Web servers;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Global Telecommunications Conference (GLOBECOM 2011), 2011 IEEE
Conference_Location :
Houston, TX, USA
ISSN :
1930-529X
Print_ISBN :
978-1-4244-9266-4
Electronic_ISBN :
1930-529X
Type :
conf
DOI :
10.1109/GLOCOM.2011.6133798
Filename :
6133798
Link To Document :
بازگشت