...
首页> 外文期刊>Computer networks >Defense techniques for low-rate DoS attacks against application servers
【24h】

Defense techniques for low-rate DoS attacks against application servers

机译:针对应用服务器的低速DoS攻击的防御技术

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

Low-rate denial of service (DoS) attacks have recently emerged as new strategies for denying networking services. Such attacks are capable of discovering vulnerabilities in protocols or applications behavior to carry out a DoS with low-rate traffic. In this paper, we focus on a specific attack: the low-rate DoS attack against application servers, and address the task of finding an effective defense against this attack.Different approaches are explored and four alternatives to defeat these attacks are suggested. The techniques proposed are based on modifying the way in which an application server accepts incoming requests. They focus on protective measures aimed at (ⅰ) preventing an attacker from capturing all the positions in the incoming queues of applications, and (ⅱ) randomizing the server operation to eliminate possible vulnerabilities due to predictable behaviors.We extensively describe the suggested techniques, discussing the benefits and drawbacks for each under two criteria: the attack efficiency reduction obtained, and the impact on the normal operation of the server. We evaluate the proposed solutions in a both a simulated and a real environment, and provide guidelines for their implementation in a production system.
机译:低速拒绝服务(DoS)攻击最近作为拒绝网络服务的新策略而出现。此类攻击能够发现协议或应用程序行为中的漏洞,从而以低速率流量执行DoS。在本文中,我们将重点放在一种特定的攻击上:针对应用服务器的低速DoS攻击,并解决找到有效防御此攻击的任务。探讨了不同的方法,并提出了应对这些攻击的四种替代方法。提出的技术基于修改应用程序服务器接受传入请求的方式。它们着重于保护措施,旨在(ⅰ)防止攻击者捕获应用程序传入队列中的所有位置,以及(ⅱ)随机化服务器操作以消除由于可预测行为引起的可能的漏洞。在两个标准下,每种技术的优缺点:降低了攻击效率,以及对服务器正常运行的影响。我们在模拟和真实环境中评估提出的解决方案,并为在生产系统中实施这些解决方案提供指导。

著录项

  • 来源
    《Computer networks》 |2010年第15期|p.2711-2727|共17页
  • 作者单位

    Dept. of Signal Theory, Telematics and Communications, E.T.S. Computer and Telecommunications Engineering, University of Granada, c/Daniel Saucedo Aranda, s, 18071 Granada, Spain;

    Dept. of Signal Theory, Telematics and Communications, E.T.S. Computer and Telecommunications Engineering, University of Granada, c/Daniel Saucedo Aranda, s, 18071 Granada, Spain;

    Dept. of Signal Theory, Telematics and Communications, E.T.S. Computer and Telecommunications Engineering, University of Granada, c/Daniel Saucedo Aranda, s, 18071 Granada, Spain;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    denial of service; low-rate; defense; network security;

    机译:拒绝服务;低利率;防御;网络安全;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号