首页> 外文期刊>Communications Surveys & Tutorials, IEEE >DDoS Attacks at the Application Layer: Challenges and Research Perspectives for Safeguarding Web Applications
【24h】

DDoS Attacks at the Application Layer: Challenges and Research Perspectives for Safeguarding Web Applications

机译:应用程序层的DDoS攻击:维护Web应用程序的挑战和研究前景

获取原文
获取原文并翻译 | 示例

摘要

Distributed denial of service (DDoS) attacks are some of the most devastating attacks against Web applications. A large number of these attacks aim to exhaust the network bandwidth of the server, and are called network layer DDoS attacks. They are volumetric attacks and rely on a large volume of network layer packets to throttle the bandwidth. However, as time passed, network infrastructure became more robust and defenses against network layer attacks also became more advanced. Recently, DDoS attacks have started targeting the application layer. Unlike network layer attacks, these attacks can be carried out with a relatively low attack volume. They also utilize legitimate application layer requests, which makes it difficult for existing defense mechanisms to detect them. These attacks target a wide variety of resources at the application layer and can bring a server down much faster, and with much more stealth, than network layer DDoS attacks. Over the past decade, research on application layer DDoS attacks has focused on a few classes of these attacks. This paper attempts to explore the entire spectrum of application layer DDoS attacks using critical features that aid in understanding how these attacks can be executed. defense mechanisms against the different classes of attacks are also discussed with special emphasis on the features that aid in the detection of different classes of attacks. Such a discussion is expected to help researchers understand why a particular group of features are useful in detecting a particular class of attacks.
机译:分布式拒绝服务(DDoS)攻击是针对Web应用程序的最具破坏性的攻击。这些攻击中有大量旨在耗尽服务器的网络带宽,被称为网络层DDoS攻击。它们是体积攻击,并依赖大量网络层数据包来限制带宽。但是,随着时间的流逝,网络基础架构变得更加强大,针对网络层攻击的防御也变得更加先进。最近,DDoS攻击已开始针对应用层。与网络层攻击不同,这些攻击可以以较低的攻击量进行。它们还利用合法的应用程序层请求,这使得现有防御机制很难检测到它们。与网络层DDoS攻击相比,这些攻击针对应用程序层的各种资源,可以使服务器停机更快,并且具有更多的隐身性。在过去的十年中,对应用程序层DDoS攻击的研究集中在这些攻击的几类上。本文尝试使用有助于理解如何执行这些攻击的关键功能来探索应用程序层DDoS攻击的整个范围。还讨论了针对不同类型攻击的防御机制,并特别强调了有助于检测不同类型攻击的功能。预期这样的讨论将有助于研究人员理解为什么特定的一组功能对于检测特定类别的攻击有用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号