Use of access characteristics to distinguish legitimate user traffic from DDoS attack traffic

Use of access characteristics to distinguish legitimate user traffic from DDoS attack traffic
复制标题

利用访问特征区分合法用户流量和DDoS攻击流量

DOI:
10.1007/s10015-019-00527-z
复制
发表时间:
2019
影响因子:
0.9
通讯作者:
Okazaki Naonobu
Okazaki Naonobu
中科院分区:
--
文献类型:
--
作者:
Aburada Kentaro;Arikawa Yuki;Usuzaki Shotaro;Yamaba Hisaaki;Katayama Tetsuro;Park Mirang;Okazaki Naonobu

文献摘要

参考文献

被引文献

相似文献

分布式拒绝服务攻击是当前信息社会的一种严重威胁,互联网作为基础设施发挥着重要作用。我们一直在研究使用一种区分合法用户和攻击的方法来缓解这些攻击。我们之前的方法是不够的,因为它只分析攻击后的访问日志。在这项研究中,我们提出了一种新的方法,可以在服务运行时区分合法用户和攻击。当入侵检测系统检测到攻击时,隔离服务器使用访问特征来区分合法用户。访问特征为:(1)用户跟踪链接;(2)发送者访问热门页面;(3)发送者当前的平均传输间隔。实验证明,该方法能够区分合法用户和攻击。
Distributed denial of service attacks are a serious threat in the current information society, where the Internet plays an important role as infrastructure. We have been studying ways to mitigate these attacks using a method that distinguishes between legitimate users and attacks. Our previous method was not sufficient because it only analyzed access logs after the attack. In this study, we propose a new method that can distinguish between legitimate users and attacks while the services are running. When the IDS detects an attack, a quarantine server distinguishes legitimate users using access characteristics. The access characteristics are: (1) user follows links, (2) sender accessed a popular page, and (3) the sender’s current average transmission interval. Our experiments confirmed that the proposed method can distinguish between legitimate users and attacks.
慢速 DoS 攻击的移动执行
DOI: --
发表时间: 2015
影响因子: 1
作者:
E. Cambiaso;Gianluca Papaleo;G. Chiola;M. Aiello
通讯作者: M. Aiello