科研成果详情

题名CALD: Surviving various application-layer DDoS attacks that mimic flash crowd
作者
发表日期2010
会议名称4th International Conference on Network and System Security, NSS 2010
会议录名称Proceedings - 2010 4th International Conference on Network and System Security, NSS 2010
ISBN978-1-4244-8484-3
页码247-254
会议日期1-3 Sept. 2010
会议地点Melbourne, VIC, Australia
摘要

Distributed denial of service (DDoS) attack is a continuous critical threat to the Internet. Derived from the low layers, new application-layer-based DDoS attacks utilizing legitimate HTTP requests to overwhelm victim resources are more undetectable. The case may be more serious when suchattacks mimic or occur during the flash crowd event of a popular Website. In this paper, we present the design and implementation of CALD, an architectural extension to protect Web servers against various DDoS attacks that masquerade as flash crowds. CALD provides real-time detection using mess tests but is different from other systems that use resembling methods. First, CALD uses a front-end sensor to monitor thetraffic that may contain various DDoS attacks or flash crowds. Intense pulse in the traffic means possible existence of anomalies because this is the basic property of DDoS attacks and flash crowds. Once abnormal traffic is identified, the sensor sends ATTENTION signal to activate the attack detection module. Second, CALD dynamically records the average frequency of each source IP and check the total mess extent. Theoretically, the mess extent of DDoS attacks is larger than the one of flash crowds. Thus, with some parameters from the attack detection module, the filter is capable of letting the legitimate requests through but the attack traffic stopped. Third, CALD may divide the security modules away from the Web servers. As a result, it keeps maximum performance on the kernel web services, regardless of the harassment from DDoS. In the experiments, the records from www.sina.com and www.taobao.com have proved the value of CALD. © 2010 IEEE.

关键词Application-layer DDoS Information theory Kalman filter
DOI10.1109/NSS.2010.69
URL查看来源
语种英语English
引用统计
被引频次[WOS]:0   [WOS记录]     [WOS相关记录]
文献类型会议论文
条目标识符https://repository.uic.edu.cn/handle/39GCC9TT/4521
专题个人在本单位外知识产出
作者单位
1.Central South University, Changsha, Hunan 410083, China
2.Deakin University, Melbourne 3125, Australia
3.Chongqing University, Chongqing, Sichuan 40044, China
推荐引用方式
GB/T 7714
Wen, Sheng,Jia, Weijia,Zhou, Weiet al. CALD: Surviving various application-layer DDoS attacks that mimic flash crowd[C], 2010: 247-254.
条目包含的文件
条目无相关文件。
个性服务
查看访问统计
谷歌学术
谷歌学术中相似的文章
[Wen, Sheng]的文章
[Jia, Weijia]的文章
[Zhou, Wei]的文章
百度学术
百度学术中相似的文章
[Wen, Sheng]的文章
[Jia, Weijia]的文章
[Zhou, Wei]的文章
必应学术
必应学术中相似的文章
[Wen, Sheng]的文章
[Jia, Weijia]的文章
[Zhou, Wei]的文章
相关权益政策
暂无数据
收藏/分享
所有评论 (0)
暂无评论
 

除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。