HTTP-SoLDiER: An HTTP-flooding attack detection scheme with the large deviation principle

HTTP-SoLDiER: An HTTP-flooding attack detection scheme with the large deviation principle
复制标题

HTTP-SoLDiER:一种大偏差原理的HTTP-flood攻击检测方案

DOI:
10.1007/s11432-013-5015-2
复制
发表时间:
2014-10-01
影响因子:
8.8
通讯作者:
Xu Jie
Xu Jie
中科院分区:
计算机科学2区
文献类型:
--
作者:
Wang Jin;Yang XiaoLong;Xu Jie

文献摘要

被引文献

相似文献

HTTP-flooding 攻击是一种更加隐蔽的分布式拒绝服务 (DDoS) 攻击,严重挑战 Web 服务的生存能力。观察网络访问行为,我们发现正常用户的上网偏好与网页流行度比恶意用户更加一致。基于这一观察,本文提出了一种新颖的 HTTP 泛洪检测方案(HTTP-SoLDiER)。具体来说,HTTP-SoLDiER首先以大偏差原则量化网络用户的上网偏好与网页流行度之间的一致性。然后HTTP-SoLDiER根据大偏差概率区分恶意用户和正常用户。在实践中,网页流行度在HTTP-SoLDiER的攻击检测中起着关键作用。由于网页内容的不断更新以及攻击者的干扰,网页的受欢迎程度往往会随着时间的推移而变化。因此,动态更新网页流行度对于 HTTP-SoLDiER 至关重要。我们设计了一种可逆指数加权移动平均(EWMA)算法来解决该问题。最后,我们通过 NS-3 模拟在真阳性 (TP) 和假阳性 (FP) 概率方面评估该方案的有效性。仿真结果表明,HTTP-SoLDiER 可以检测到所有随机 HTTP 洪泛攻击者和大多数完全知识的 HTTP 洪泛攻击者,且误报率极低。
HTTP-flooding attack is a much stealthier distributed denial of service (DDoS) attack, challenging the survivability of the web services seriously. Observing the web access behavior, we find that the surfing preference of normal users is much more consistent with the webpage popularity than that of malicious users. Based on this observation, this paper proposes a novel detection scheme for HTTP-flooding (HTTP-SoLDiER). Specifically, HTTP-SoLDiER first quantifies the consistency between web users surfing preference and the webpage popularity with large-deviation principle. Then HTTP-SoLDiER distinguishes the malicious users from normal ones according to the large-deviation probability. In practice, the webpage popularity plays a key role in attack detection of HTTP-SoLDiER. Due to the never-ending updating of the webpage content and the disturbance induced by attackers, the webpage popularity often varies over time. Thus, it is critical for HTTP-SoLDiER to dynamically update the webpage popularity. We design a reversible exponentially weighted moving average (EWMA) algorithm to solve the problem. Finally, we evaluate the effectiveness of this scheme in terms of true positive (TP) and false positive (FP) probabilities with NS-3 simulations. The simulation results show that HTTP-SoLDiER can detect all random HTTP-flooding attackers and most of the perfect-knowledge HTTP-flooding attackers at little false positive.