首页> 外文会议>IEEE Joint Intelligence and Security Informatics Conference >A Selective Defense for Application Layer DDoS Attacks
【24h】

A Selective Defense for Application Layer DDoS Attacks

机译:应用层DDOS攻击的选择性防御

获取原文
获取外文期刊封面目录资料

摘要

Distributed Denial of Service (DDoS) attacks remain among the most dangerous and noticeable attacks on the Internet. Differently from previous attacks, many recent DDoS attacks have not been carried out over the network layer, but over the application layer. The main difference is that in the latter, an attacker can target a particular application of the server, while leaving the remaining applications still available, thus generating less traffic and being harder to detect. Such attacks are possible by exploiting application layer protocols used by the target application. This paper proposes a novel defense for Application Layer DDoS attacks (ADDoS) based on the Adaptive Selective Verification (ASV) defense used for mitigating Network Layer DDoS attacks. We formalize our defense mechanism in the computational system Maude and demonstrate by using the statistical model checker PVeStA that it can be used to prevent ADDoS. In particular, we show that even in the presence of a great number of attackers, an application running our defense still has high levels of availability. Moreover, we compare our results to a defense based on traffic monitoring proposed in the literature and show that our defense is more robust and also leads to less traffic.
机译:分布式拒绝服务(DDOS)攻击仍然是互联网上最危险和明显的攻击之一。与以前的攻击不同,许多最近的DDOS攻击尚未通过网络层进行,而是在应用层上进行。主要区别在于,在后者中,攻击者可以针对服务器的特定应用,同时留下剩余的应用程序,从而产生较少的流量并更难检测。通过利用目标应用程序使用的应用层协议来实现这种攻击。本文提出了基于用于减轻网络层DDOS攻击的自适应选择性验证(ASV)防御的应用层DDOS攻击(addos)的新型防御。我们在计算系统Maude中将我们的防御机制正式化,并使用统计模型检查器Pvesta来证明它可用于防止addos。特别是,我们表明即使在存在大量的攻击者的情况下,运行我们的防御的应用程序仍然具有高水平的可用性。此外,我们将我们的成果与基于文献中提出的交通监测的辩护进行比较,并表明我们的防务更加强劲,并且还导致交通少。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号