...
首页> 外文期刊>Journal of land use science >SkyShield: A Sketch-Based Defense System Against Application Layer DDoS Attacks
【24h】

SkyShield: A Sketch-Based Defense System Against Application Layer DDoS Attacks

机译:Skyshield:针对应用层DDOS攻击的草图的防御系统

获取原文
获取原文并翻译 | 示例
           

摘要

Application layer distributed denial of service (DDoS) attacks have become a severe threat to the security of web servers. These attacks evade most intrusion prevention systems by sending numerous benign HTTP requests. Since most of these attacks are launched abruptly and severely, a fast intrusion prevention system is desirable to detect and mitigate these attacks as soon as possible. In this paper, we propose an effective defense system, named SkyShield, which leverages the sketch data structure to quickly detect and mitigate application layer DDoS attacks. First, we propose a novel calculation of the divergence between two sketches, which alleviates the impact of network dynamics and improves the detection accuracy. Second, we utilize the abnormal sketch to facilitate the identification of malicious hosts of an ongoing attack. This improves the efficiency of SkyShield by avoiding the reverse calculation of malicious hosts. We have developed a prototype of SkyShield and carefully evaluated its effectiveness using real attack data collected from a large-scale web cluster. The experimental results show that SkyShield can quickly reduce malicious requests, while posing a limited impact on normal users.
机译:应用层分布式拒绝服务(DDOS)攻击已成为Web服务器安全性的严重威胁。这些攻击通过发送众多良性的HTTP请求来避免最侵扰的预防系统。由于大多数这些攻击突然和严重发动,因此可以尽快检测和减轻这些攻击的快速入侵防御系统。在本文中,我们提出了一个名为Skyshield的有效防御系统,它利用草图数据结构快速检测和减轻应用层DDOS攻击。首先,我们提出了一种新颖的计算两种草图之间的分歧,这减轻了网络动态的影响并提高了检测精度。其次,我们利用异常草图来促进持续攻击的恶意宿主。通过避免对恶意主机的反向计算来提高Skyshield的效率。我们开发了Skyshield的原型,并使用从大型Web集群中收集的实际攻击数据仔细评估其有效性。实验结果表明,Skyshield可以快速减少恶意请求,同时对普通用户产生有限的影响。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号