Aldd: A Hybrid Traffic-User Behavior Detection Method For Application Layer Ddos

2018 17TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (IEEE TRUSTCOM) / 12TH IEEE INTERNATIONAL CONFERENCE ON BIG DATA SCIENCE AND ENGINEERING (IEEE BIGDATASE)(2018)

引用 27|浏览34
暂无评分
摘要
Distributed Denial of Service (DDoS) has been one of the most critical threats to internet applications and web services. Especially with the current advances in network technology, many attackers resort to application layer DDoS (ALDDoS) which utilizes legitimate requests to overwhelm the victim servers. Under this kind of attack, the single request content can be highly similar to normal ones, and this renders previous traffic features-based detectionmethods void. In this paper, we are addressing two common issues in ALDDoS detection methods: the inaccuracy of traffic feature based detecting algorithms, and the time and space complexity of user behavior-based detecting algorithms. Different from the existing detection pattern for each request, the detection pattern used in this paper is for a time window. We extract instances of traffic and user behaviors from web server logs, and propose a hybrid traffic-user behavior detection method for ALDDoS. Neutral network is adopted for further cluster analysis. Experimental results on the recent public dataset CICIDS2017 indicate that the proposed method can achieve high detection accuracy while reducing 90% of time cost.
更多
查看译文
关键词
Application Layer DDoS, feature selection, traffic-user behavior, neutral network
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要