首页> 外文期刊>Computer Communications >Detecting latent attack behavior from aggregated Web traffic
【24h】

Detecting latent attack behavior from aggregated Web traffic

机译:从聚合的Web流量中检测潜在的攻击行为

获取原文
获取原文并翻译 | 示例
           

摘要

Indirect attack mode has been a serious threat to server security due to the covert nature. This paper focuses on a new application-layer indirect attack which exploits the communication mechanism of proxy server to attack the targets. Such type of attacks is not easy to be discovered by most existing defense systems since malicious traffic hides in the aggregated traffic. Moreover, the sources of the attack traffic and normal traffic are indistinguishable, because both of them share the same IP of the last proxy server. In this paper a novel server-side defense scheme is proposed to resist such covert indirect attacks. An improved semi-Markov model is proposed to describe the dynamic behavior process of aggregated traffic. The model includes two stochastic processes. The observable process represents the changes in the appearance features of the observed traffic, while the unobservable process is a semi-Markov chain which represents the underlying time-varying patterns used to generate the outgoing traffic by a proxy server. An algorithm is proposed to estimate the model parameters. An objective function is defined to evaluate the normality of a proxy server's access behavior. Numerical results based on real traffic demonstrate the performance of the proposed method.
机译:由于隐蔽性,间接攻击模式已严重威胁服务器安全。本文重点研究一种新的应用程序层间接攻击,它利用代理服务器的通信机制来攻击目标。由于恶意流量隐藏在聚合流量中,因此大多数现有防御系统都不容易发现这种类型的攻击。而且,攻击流量和正常流量的来源是无法区分的,因为它们都共享最后一个代理服务器的相同IP。在本文中,提出了一种新颖的服务器端防御方案来抵抗这种隐秘的间接攻击。提出了一种改进的半马尔可夫模型来描述聚集交通的动态行为过程。该模型包括两个随机过程。可观察的过程表示观察到的流量的外观特征的变化,而不可观察的过程是半马尔可夫链,它表示用于由代理服务器生成传出流量的基础时变模式。提出了一种估计模型参数的算法。定义了一个目标函数来评估代理服务器访问行为的正常性。基于实际流量的数值结果证明了该方法的性能。

著录项

  • 来源
    《Computer Communications》 |2013年第8期|895-907|共13页
  • 作者单位

    School of Information Science and Technology, Sun Yat-Sen University, Guangzhou 510275, China;

    Department of Engineering Technology, Missouri Western State University St. Joseph, MO 64507, USA;

    Network and Information Technology Center, Sun Yat-Sen University, Guangzhou 510275, China;

    School of Computer Science and Engineering, Guilin University of Electronic Technology, Guilin 541004, China;

    School of Information Science and Technology, Sun Yat-Sen University, Guangzhou 510275, China;

  • 收录信息 美国《科学引文索引》(SCI);美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    indirect attack; implicit attack; attack detection; aggregated traffic;

    机译:间接攻击;隐式攻击;攻击检测;流量汇总;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号