首页> 外文会议>International Conference on Information, Intelligence, Systems and Applications >Evaluating security controls against HTTP-based DDoS attacks
【24h】

Evaluating security controls against HTTP-based DDoS attacks

机译:评估针对基于HTTP的DDoS攻击的安全控制

获取原文

摘要

Distributed Denial of Service attacks generally require a botmaster controlling a large number of infected systems (bots) in order to take down a target service. However, more recent DDoS attacks targeting at the HTTP layer can be very effective even with a small number of infected bots. In this paper we analyze DDoS attacks which require only a small number of bots to render a web server unavailable. In order to study their behavior, we implement a Botnet system in a test environment. We simulate bots by using both Linux and Windows-based systems infected with Slowloris, an HTTP syn-flooder, targeting to a vulnerable Apache web server. We apply several security controls in order to test their effectiveness against such attacks. Our results show that only a combination of carefully selected anti-DDoS controls can significantly reduce the exposure to such attacks without affecting the provided service.
机译:分布式拒绝服务攻击通常需要僵尸程序管理员控制大量受感染的系统(僵尸程序)才能删除目标服务。但是,即使使用少量受感染的漫游器,针对HTTP层的最新DDoS攻击也可能非常有效。在本文中,我们分析了DDoS攻击,该攻击只需要少量的漫游器就可以使Web服务器不可用。为了研究其行为,我们在测试环境中实现了僵尸网络系统。我们通过使用感染了Slowloris(一种HTTP合成器)的Linux和Windows系统来模拟机器人,该系统针对易受攻击的Apache Web服务器。我们应用了几种安全控制措施,以测试其针对此类攻击的有效性。我们的结果表明,只有精心选择的反DDoS控件组合才能在不影响所提供服务的情况下显着减少遭受此类攻击的风险。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号