Use of access characteristics to distinguish legitimate user traffic from DDoS attack traffic
Use of access characteristics to distinguish legitimate user traffic from DDoS attack traffic
复制标题
利用访问特征区分合法用户流量和DDoS攻击流量
DOI:
10.1007/s10015-019-00527-z
复制
发表时间:
2019
影响因子:
0.9
通讯作者:
Okazaki Naonobu
中科院分区:
文献类型:
--
作者:
Aburada Kentaro;Arikawa Yuki;Usuzaki Shotaro;Yamaba Hisaaki;Katayama Tetsuro;Park Mirang;Okazaki Naonobu
Distributed denial of service attacks are a serious threat in the current information society, where the Internet plays an important role as infrastructure. We have been studying ways to mitigate these attacks using a method that distinguishes between legitimate users and attacks. Our previous method was not sufficient because it only analyzed access logs after the attack. In this study, we propose a new method that can distinguish between legitimate users and attacks while the services are running. When the IDS detects an attack, a quarantine server distinguishes legitimate users using access characteristics. The access characteristics are: (1) user follows links, (2) sender accessed a popular page, and (3) the sender’s current average transmission interval. Our experiments confirmed that the proposed method can distinguish between legitimate users and attacks.
影响因子:
1
作者:
E. Cambiaso;Gianluca Papaleo;G. Chiola;M. Aiello
通讯作者:
M. Aiello