Measurement-Based Analysis of a DoS Defense Module for an Open Source Web Server

被引:4
|
作者
Catillo, Marta [1 ]
Pecchia, Antonio [1 ]
Villano, Umberto [1 ]
机构
[1] Univ Sannio, Dipartimento Ingn, Benevento, Italy
来源
关键词
Denial of Service; Web server; Defense; Availability; ATTACKS; SERVICE;
D O I
10.1007/978-3-030-64881-7_8
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Denial of Service (DoS) attacks represent an ever evolving landscape, which ranges from bruteforce flooding approaches to more sophisticated low-bandwidth slow techniques. DoS has become a major threat to the availability of modern web servers because of the large number of attack tools across the Internet. In spite of the increasing number of security modules that can be usefully deployed in production servers, there is not a one-fits-all defense solution against DoS. This paper proposes a measurement-based analysis of a well-established defense module for the Apache web server. The module is tested against both flooding and slow DoS attacks in order to quantify its capability at assuring correct service to legitimate clients. Results indicate that the module can mitigate flooding DoS attacks while causing some performance loss of the server; however, it is ineffective against slow attacks. The findings of our analysis are useful to support the deployment of proper defense mechanisms.
引用
收藏
页码:121 / 134
页数:14
相关论文
共 50 条
  • [1] A measurement-based approach for estimating error rate of a web server system
    Xiao, X. (xiaoxiao@rel.hiroshima-u.ac.jp), 1600, Inderscience Enterprises Ltd., 29, route de Pre-Bois, Case Postale 856, CH-1215 Geneva 15, CH-1215, Switzerland (07):
  • [2] Measurement-Based Optimization of Server License Balancing
    Neumann, Robert
    Fiegler, Anja
    Poehls, Marcus
    Dumke, Reiner R.
    PROCEEDINGS OF 2016 JOINT CONFERENCE OF THE INTERNATIONAL WORKSHOP ON SOFTWARE MEASUREMENT AND THE INTERNATIONAL CONFERENCE ON SOFTWARE PROCESS AND PRODUCT MEASUREMENT (IWSM-MENSURA), 2016, : 95 - 106
  • [3] Web Server Security on Open Source Environments
    Gkoutzelis, Dimitrios X.
    Sardis, Manolis S.
    NEXT GENERATION SOCIETY: TECHNOLOGICAL AND LEGAL ISSUES, 2010, 26 : 236 - +
  • [4] No more DoS? An empirical study on defense techniques for web server Denial of Service mitigation
    Catillo, Marta
    Pecchia, Antonio
    Villano, Umberto
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2022, 202
  • [5] A study of measurement-based Web prefetch control
    Wang, L
    Zhang, LF
    Shu, YT
    Dong, M
    Yang, OWW
    2000 CANADIAN CONFERENCE ON ELECTRICAL AND COMPUTER ENGINEERING, CONFERENCE PROCEEDINGS, VOLS 1 AND 2: NAVIGATING TO A NEW ERA, 2000, : 204 - 208
  • [6] A measurement-based simulation model of a web cluster
    Wagner, I
    Hielscher, KS
    German, R
    ISC'2005: 3RD INDUSTRIAL SIMULATION CONFERENCE 2005, 2005, : 88 - 92
  • [7] Measurement-based IoT Server Selection for Mobile Edge Computing
    Bhooanusas, Nuntanut
    Sou, Sok-Ian
    2021 22ND ASIA-PACIFIC NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM (APNOMS), 2021, : 17 - 20
  • [8] Measurement-Based Timing Analysis
    Wenzel, Ingomar
    Kirner, Raimund
    Rieder, Bernhard
    Puschner, Peter
    Communications in Computer and Information Science, 2009, 17 : 430 - 444
  • [9] Measurement-Based Timing Analysis
    Wenzel, Ingomar
    Kirner, Raimund
    Rieder, Bernhard
    Puschner, Peter
    LEVERAGING APPLICATIONS OF FORMAL METHODS, VERIFICATION AND VALIDATION, PROCEEDINGS, 2008, 17 : 430 - 444
  • [10] A measurement-based analysis of multihoming
    Akella, A
    Maggs, B
    Seshan, S
    Shaikh, A
    Sitaraman, R
    ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2003, 33 (04) : 353 - 364