CALD : surviving various application-layer DDoS attacks that mimic flash crowd


Autoria(s): Wen, Sheng; Jia, Weijia; Zhou, Wei; Zhou, Wanlei; Xu, Chuan
Contribuinte(s)

Xiang, Yang

Samarati, Pierangela

Hu, Jiankun

Zhou, Wanlei

Sadeghi, Ahmad-Reza

Data(s)

01/01/2010

Resumo

Distributed denial of service (DDoS) attack is a continuous critical threat to the Internet. Derived from the low layers, new application-layer-based DDoS attacks utilizing legitimate HTTP requests to overwhelm victim resources are more undetectable. The case may be more serious when suchattacks mimic or occur during the flash crowd event of a popular Website. In this paper, we present the design and implementation of CALD, an architectural extension to protect Web servers against various DDoS attacks that masquerade as flash crowds. CALD provides real-time detection using mess tests but is different from other systems that use resembling methods. First, CALD uses a front-end sensor to monitor thetraffic that may contain various DDoS attacks or flash crowds. Intense pulse in the traffic means possible existence of anomalies because this is the basic property of DDoS attacks and flash crowds. Once abnormal traffic is identified, the sensor sends ATTENTION signal to activate the attack detection module. Second, CALD dynamically records the average frequency of each source IP and check the total mess extent. Theoretically, the mess extent of DDoS attacks is larger than the one of flash crowds. Thus, with some parameters from the attack detection module, the filter is capable of letting the legitimate requests through but the attack traffic stopped. Third, CALD may divide the security modules away from the Web servers. As a result, it keeps maximum performance on the kernel web services, regardless of the harassment from DDoS. In the experiments, the records from www.sina.com and www.taobao.com have proved the value of CALD.

Identificador

http://hdl.handle.net/10536/DRO/DU:30033643

Idioma(s)

eng

Publicador

IEEE

Relação

http://dro.deakin.edu.au/eserv/DU:30033643/zhou-caldsurviving-2010.pdf

http://dro.deakin.edu.au/eserv/DU:30033643/zhou-nssconference-2010.pdf

http://anss.org.au/nss2010/

http://dx.doi.org/10.1109/NSS.2010.69

Direitos

2010, by The Institute of Electrical and Electronics Engineers, Inc. All rights reserved

Palavras-Chave #DDoS #application-layer #Kalman Filter #information theory
Tipo

Conference Paper