Defending Web Servers Against Flash Crowd Attacks

Defending Web Servers Against Flash Crowd Attacks
复制标题

保护 Web 服务器免受 Flash Crowd 攻击

DOI:
--
复制
发表时间:
2019
期刊:
IEEE International Conference on Network Protocols
影响因子:
--
通讯作者:
J. Mirkovic
J. Mirkovic
中科院分区:
--
文献类型:
--
作者:
R. Tandon;Abhinav Palia;J. Ramani;Brandon Paulsen;G. Bartlett;J. Mirkovic

文献摘要

被引文献

相似文献

Flash Crowd Attacks(FCA)是一种DDoS攻击,它通过大量僵尸程序生成的格式良好的请求来淹没受害者服务,例如Web服务器。很难检测和过滤此类攻击,因为合法请求和攻击请求看起来完全相同。在我们以前的工作中,我们提出了人类用户如何与Web服务器交互的模型,并在模拟中表明这些模型可以检测到幼稚的FCA攻击。我们显着扩展这些提出的模型,使它们更强大,更简单,适用于更广泛的FCA攻击在本文中。我们实现的模型在一个系统中称为FRADE,并评估它在三个Web服务器上具有不同的服务器应用程序和不同的内容。我们表明,FRADE可以在几秒钟内检测到幼稚和复杂的机器人,并成功地过滤出攻击流量。因此,FRADE要求攻击者部署的僵尸网络至少比目前的僵尸网络大三个数量级,从而大大提高了成功攻击的门槛。
Flash Crowd Attacks (FCAs) are DDoS attacks that flood victim services, such as Web servers, with well-formed requests, generated by numerous bots. It is hard to detect and filter such attacks because both legitimate and attack requests look identical. In our previous work [1], we proposed models of how human users interact with Web servers, and also showed in simulation that these models can detect naive FCA attacks. We significantly extend these proposed models to make them more robust, simpler, and applicable to a wider variety of FCA attacks in this paper. We implement the models in a system called FRADE, and evaluate it on three Web servers with different server applications and different content. We show that FRADE can detect both naive and sophisticated bots within seconds and successfully filters out attack traffic. Therefore, FRADE significantly raises the bar for a successful attack by requiring attackers to deploy botnets that are at least three orders of magnitude larger than the botnets today.