Measurement-Based Analysis of a DoS Defense Module for an Open Source Web Server

被引:4
|
作者
Catillo, Marta [1 ]
Pecchia, Antonio [1 ]
Villano, Umberto [1 ]
机构
[1] Univ Sannio, Dipartimento Ingn, Benevento, Italy
来源
关键词
Denial of Service; Web server; Defense; Availability; ATTACKS; SERVICE;
D O I
10.1007/978-3-030-64881-7_8
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Denial of Service (DoS) attacks represent an ever evolving landscape, which ranges from bruteforce flooding approaches to more sophisticated low-bandwidth slow techniques. DoS has become a major threat to the availability of modern web servers because of the large number of attack tools across the Internet. In spite of the increasing number of security modules that can be usefully deployed in production servers, there is not a one-fits-all defense solution against DoS. This paper proposes a measurement-based analysis of a well-established defense module for the Apache web server. The module is tested against both flooding and slow DoS attacks in order to quantify its capability at assuring correct service to legitimate clients. Results indicate that the module can mitigate flooding DoS attacks while causing some performance loss of the server; however, it is ineffective against slow attacks. The findings of our analysis are useful to support the deployment of proper defense mechanisms.
引用
收藏
页码:121 / 134
页数:14
相关论文
共 50 条
  • [31] A measurement-based power consumption model of a server by considering inlet air temperature
    Jin, Chaoqiang
    Bai, Xuelian
    Zhang, Xin
    Xu, Xin
    Tang, Yu
    Zeng, Chao
    ENERGY, 2022, 261
  • [32] Research on Attack-defense Technology Based on Web Server Side
    Gao, He
    Shi, Yijie
    Gao, Yan
    Zhang, Qiuyu
    PROCEEDINGS OF THE 2015 3RD INTERNATIONAL CONFERENCE ON MACHINERY, MATERIALS AND INFORMATION TECHNOLOGY APPLICATIONS, 2015, 35 : 1684 - 1688
  • [33] Queuing theory based open loop control of web server
    Kumar, KH
    Majhi, S
    PROCEEDINGS OF THE 2004 AMERICAN CONTROL CONFERENCE, VOLS 1-6, 2004, : 2314 - 2315
  • [34] K-Test: An Analytical Model for Measurement-Based Server Selection Based on Response Time
    Sou, Sok-Ian
    Bhooanusas, Nuntanut
    Lin, Yi-Bing
    Deng, Der-Jiunn
    IEEE TRANSACTIONS ON VEHICULAR TECHNOLOGY, 2023, 72 (02) : 2338 - 2351
  • [35] Revising Measurement-Based Probabilistic Timing Analysis
    Santinelli, Luca
    Guet, Fabrice
    Morio, Jerome
    PROCEEDINGS OF THE 23RD IEEE REAL-TIME AND EMBEDDED TECHNOLOGY AND APPLICATIONS SYMPOSIUM (RTAS 2017), 2017, : 199 - 208
  • [36] Measurement-Based Ring Oscillator Variation Analysis
    Johguchi, Koh
    Kaya, Akihiro
    Izumi, Shinya
    Mattausch, Hans Juergen
    Koide, Tetsushi
    Sadachika, Norio
    IEEE DESIGN & TEST OF COMPUTERS, 2010, 27 (05): : 6 - 13
  • [37] Measurement-based analysis of networked system availability
    Iyer, RK
    Kalbarczyk, Z
    Kalyanakrishnan, M
    PERFORMANCE EVALUATION: ORIGINS AND DIRECTIONS, 2000, 1769 : 161 - 199
  • [38] Server-Based Computing Solution Based on Open Source Software
    Niemi, Tapio
    Tuisku, Miika
    Hameri, Ari-pekka
    Curtin, Tamara
    INFORMATION SYSTEMS MANAGEMENT, 2009, 26 (01) : 77 - 86
  • [39] Using a runtime measurement device with measurement-based WCET analysis
    Rieder, Bernhard
    Wenzel, Ingomar
    Steinhammer, Klaus
    Puschner, Peter
    EMBEDDED SYSTEM DESIGN: TOPICS, TECHNIQUES AND TRENDS, 2007, 231 : 15 - +
  • [40] Research on measurement-based rejuvenation analytical models for a single-server virtualized system
    Zhong, Yi
    Xu, Jian
    Zhang, Hong
    Liu, Fengyu
    Zhong, Y. (zhongyi@njust.edu.cn), 1600, Binary Information Press, P.O. Box 162, Bethel, CT 06801-0162, United States (09): : 9611 - 9618