...
首页> 外文期刊>Journal of ambient intelligence and humanized computing >ConnectionScore: a statistical technique to resist application-layer DDoS attacks
【24h】

ConnectionScore: a statistical technique to resist application-layer DDoS attacks

机译:ConnectionScore:一种统计技术,可抵抗应用程序层DDoS攻击

获取原文
获取原文并翻译 | 示例
           

摘要

In an application-layer distributed denial of service (DDoS) attack, zombie machines send a large number of legitimate requests to the victim server. Since these requests have legitimate formats and are sent through normal TCP connections, intrusion detection systems cannot detect them. In these attacks, an adversary does not saturate the bandwidth of the victim server through inbound traffic, but through outbound traffic. The next aim of the adversary is to consume and exhaust computational resources (e.g., CPU cycles), memory resources, TCP/IP stack, resources of input/output devices, etc. This paper proposes a novel scheme which is called ConnectionScore to resist such DDoS attacks. During the attack time, any connection is scored based on history and statistical analysis which has been done during the normal condition. The bottleneck resources are retaken from those connections which take lower scores. Our analysis shows that connections established by the adversary give low scores. In fact, the ConnectionScore technique can estimate legitimacy of connections with high probability. The rate of suspicious connections being dropped is adjusted based on the current level of overload of the server and a threshold-level of free resources. To evaluate the performance of the scheme, we perform experiments in the Emulab environment using real traceroute data of the ClarkNet WWW server.
机译:在应用程序层分布式拒绝服务(DDoS)攻击中,僵尸计算机将大量合法请求发送到受害服务器。由于这些请求具有合法格式并通过普通的TCP连接发送,因此入侵检测系统无法检测到它们。在这些攻击中,对手不会通过入站流量,而是通过出站流量,使受害者服务器的带宽饱和。对手的下一个目标是消耗和耗尽计算资源(例如,CPU周期),内存资源,TCP / IP堆栈,输入/输出设备的资源等。本文提出了一种新颖的方案,称为ConnectionScore来抵制此类攻击。 DDoS攻击。在攻击期间,将根据正常情况下进行的历史记录和统计分析对任何连接进行评分。瓶颈资源从那些得分较低的连接中获取。我们的分析表明,对手建立的联系得分较低。实际上,ConnectionScore技术可以高概率估计连接的合法性。根据服务器的当前过载级别和可用资源的阈值级别来调整丢弃可疑连接的速率。为了评估该方案的性能,我们使用ClarkNet WWW服务器的真实跟踪路由数据在Emulab环境中进行了实验。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号