Measurement-Based Analysis of a DoS Defense Module for an Open Source Web Server

被引:4
|
作者
Catillo, Marta [1 ]
Pecchia, Antonio [1 ]
Villano, Umberto [1 ]
机构
[1] Univ Sannio, Dipartimento Ingn, Benevento, Italy
来源
关键词
Denial of Service; Web server; Defense; Availability; ATTACKS; SERVICE;
D O I
10.1007/978-3-030-64881-7_8
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Denial of Service (DoS) attacks represent an ever evolving landscape, which ranges from bruteforce flooding approaches to more sophisticated low-bandwidth slow techniques. DoS has become a major threat to the availability of modern web servers because of the large number of attack tools across the Internet. In spite of the increasing number of security modules that can be usefully deployed in production servers, there is not a one-fits-all defense solution against DoS. This paper proposes a measurement-based analysis of a well-established defense module for the Apache web server. The module is tested against both flooding and slow DoS attacks in order to quantify its capability at assuring correct service to legitimate clients. Results indicate that the module can mitigate flooding DoS attacks while causing some performance loss of the server; however, it is ineffective against slow attacks. The findings of our analysis are useful to support the deployment of proper defense mechanisms.
引用
收藏
页码:121 / 134
页数:14
相关论文
共 50 条
  • [21] MEASUREMENT-BASED ANALYSIS OF ERROR LATENCY
    CHILLAREGE, R
    IYER, RK
    IEEE TRANSACTIONS ON COMPUTERS, 1987, 36 (05) : 529 - 537
  • [22] Measurement-based performance analysis of e-commerce applications with web services components
    Datla, V
    Goseva-Popstojanova, K
    ICEBE 2005: IEEE INTERNATIONAL CONFERENCE ON E-BUSINESS ENGINEERING, PROCEEDINGS, 2005, : 305 - 314
  • [23] A measurement-based ageing analysis of the JVM
    Cotroneo, Domenico
    Orlando, Salvatore
    Pietrantuono, Roberto
    Russo, Stefano
    SOFTWARE TESTING VERIFICATION & RELIABILITY, 2013, 23 (03): : 199 - 239
  • [24] A measurement-based ageing analysis of the JVM
    Cotroneo, Domenico
    Orlando, Salvatore
    Pietrantuono, Roberto
    Russo, Stefano
    Software Testing Verification and Reliability, 2013, 23 (03) : 199 - 239
  • [25] FunSet: an open-source software and web server for performing and displaying Gene Ontology enrichment analysis
    Matthew L. Hale
    Ishwor Thapa
    Dario Ghersi
    BMC Bioinformatics, 20
  • [26] Multiple Points Measurement-Based Junction Temperature Estimation of IGBT Module
    Arya, Abhinav
    Chanekar, Abhishek
    Verma, Amit
    Anand, Sandeep
    IEEE JOURNAL OF EMERGING AND SELECTED TOPICS IN POWER ELECTRONICS, 2023, 11 (03) : 3457 - 3467
  • [27] FunSet: an open-source software and web server for performing and displaying Gene Ontology enrichment analysis
    Hale, Matthew L.
    Thapa, Ishwor
    Ghersi, Dario
    BMC BIOINFORMATICS, 2019, 20 (1)
  • [28] Measurement, analysis and performance improvement of the Apache Web server
    Hu, YM
    Nanda, A
    Yang, Q
    1999 IEEE INTERNATIONAL PERFORMANCE, COMPUTING AND COMMUNICATIONS CONFERENCE, 1999, : 261 - 267
  • [29] Measurement-based Experiments on the Mobile Web: A Systematic Mapping Study
    de Munk, Omar
    Malavolta, Ivano
    PROCEEDINGS OF EVALUATION AND ASSESSMENT IN SOFTWARE ENGINEERING (EASE 2021), 2021, : 191 - 200
  • [30] Measurement-based Channel Modeling for mmWave Wireless Links in Enclosed Server Platforms
    Wang, Guangxin
    Zhan, Kai
    Kamgaing, Telesphor
    Khanna, Rahul
    Liu, Huaping
    Natarajan, Arun
    2017 IEEE RADIO AND WIRELESS SYMPOSIUM (RWS), 2017, : 141 - 143