• DocumentCode
    761768
  • Title

    Monitoring the Application-Layer DDoS Attacks for Popular Websites

  • Author

    Xie, Yi ; Yu, Shun-zheng

  • Author_Institution
    Dept. of Electr. & Commun. Eng., Sun Yat-Sen Univ., Guangzhou
  • Volume
    17
  • Issue
    1
  • fYear
    2009
  • Firstpage
    15
  • Lastpage
    25
  • Abstract
    Distributed denial of service (DDoS) attack is a continuous critical threat to the Internet. Derived from the low layers, new application-layer-based DDoS attacks utilizing legitimate HTTP requests to overwhelm victim resources are more undetectable. The case may be more serious when such attacks mimic or occur during the flash crowd event of a popular Website. Focusing on the detection for such new DDoS attacks, a scheme based on document popularity is introduced. An Access Matrix is defined to capture the spatial-temporal patterns of a normal flash crowd. Principal component analysis and independent component analysis are applied to abstract the multidimensional Access Matrix. A novel anomaly detector based on hidden semi-Markov model is proposed to describe the dynamics of Access Matrix and to detect the attacks. The entropy of document popularity fitting to the model is used to detect the potential application-layer DDoS attacks. Numerical results based on real Web traffic data are presented to demonstrate the effectiveness of the proposed method.
  • Keywords
    Internet; Markov processes; Web sites; independent component analysis; principal component analysis; telecommunication security; telecommunication traffic; HTTP requests; Internet; Web sites; Web traffic; access matrix; anomaly detector; application-layer; distributed denial of service; document popularity fitting; flash crowd event; hidden semi-Markov model; independent component analysis; principal component analysis; spatial-temporal patterns; Application-layer; distributed denial of service (DDoS); popular Website;
  • fLanguage
    English
  • Journal_Title
    Networking, IEEE/ACM Transactions on
  • Publisher
    ieee
  • ISSN
    1063-6692
  • Type

    jour

  • DOI
    10.1109/TNET.2008.925628
  • Filename
    4548145