Web page request behavior analysis for threshold based HTTP GET Flooding attack detection

Citations

SCOPUS

0

초록

The HTTP GET Flooding attack is one of the most frequently tried distributed denial-of-service (DDoS) attack. Especially, the sophisticated HTTP GET Flooding attack is very popular and has very similar traffic characteristics to normal one. So, it is quite difficult to detect it. Even though several detection algorithms are developed for the attack, they need lots of system resources [12, 13]. Sometimes due to the time consuming processes the whole performance of DDoS defense systems is degraded and it becomes another problem. For that, we propose a threshold based HTTP GET Flooding attack detection algorithm. Usually, threshold based detection methods can't detect the sophisticated DDoS attacks, but the proposed method develop a new threshold based on the HTTP GET request behavior analysis. In this algorithm, for behavior based threshold generation, we calculate the Average Inter-GET-Request-Packet- Exist-TS-Gap (AIGG) based on two special time periods. Also, the proposed algorithm doesn't need to analyze every HTTP GET request packet, so it needs less CPU resources than the algorithms which have to analyze all the request packets.

키워드

DDoS attackHTTP GET FloodingHTTP GET request behavior analysisNetwork securityThreshold based
제목
Web page request behavior analysis for threshold based HTTP GET Flooding attack detection
저자
Choi, YangseoKim, IkkyunIm, Eul Gyu
발행일
2013-08
유형
Article
저널명
Information
16
8 B
페이지
6025 ~ 6039