Web DDoS Detection Schemes Based on Measuring User's Access Behavior with Large Deviation

被引:0
|
作者
Wang, Jin [1 ]
Yang, Xiaolong [1 ]
Long, Keping [1 ]
机构
[1] Univ Elect Sci & Technol China, Res Ctr Opt Internet & Mobile Informat Network, Chengdu 611731, Peoples R China
关键词
IP network; DDoS; Large deviation; Markov process;
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Distributed denial-of-service (DDoS) attack seriously threatens the survivability of web services. It attempts to exhaust a server's resources (e. g., I/O bandwidth, CPU, and memory resources) to the extent that no resource is available for requests from legitimate users. Recently, some attackers launch web DDoS attack from the application layer (i.e., web app-DDoS), which can evade most of the existing detection approaches that mainly focused on Bandwidth-Flooding DDoS and TCP SYN-Flooding DDoS. This paper discusses the detection of web app-DDoS, and present two different models to characterize user's web access behavior, i.e., click-ratio based model and Markov process based model. With these characterizations as reference, we adopt large deviation theory to estimate the probability that each ongoing user's access behavior is "consistent" with the corresponding reference characterization, and propose two different detection schemes, LD-IID and LD-MP, respectively. We also validate our schemes with simulations, and the simulation results show that LD-IID can detect attackers accurately, yet LD-MP has high false negatives.
引用
收藏
页数:5
相关论文
共 50 条
  • [41] A Novel Lattice Based Research Frame Work for Identifying Web User's Behavior with Web Usage Mining
    Rao, V. V. R. Maheswara
    Kumari, V. Valli
    INFORMATION AND COMMUNICATION TECHNOLOGIES, 2010, 101 : 90 - +
  • [42] A semi-supervised web DDoS detection method based on manifold regularization
    Kang, Songlin
    Liu, Chuchu
    Zhu, Chengzhang
    Fan, Xiaoping
    Journal of Computational Information Systems, 2014, 10 (22): : 9723 - 9732
  • [43] Web Attack Detection Based on User Behaviour Semantics
    Zhang, Yunyi
    Lu, Jintian
    Jin, Shuyuan
    ALGORITHMS AND ARCHITECTURES FOR PARALLEL PROCESSING, ICA3PP 2020, PT III, 2020, 12454 : 459 - 474
  • [44] An adaptive detection of anomalies in user's behavior
    Sokolov, AM
    PROCEEDINGS OF THE INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS 2003, VOLS 1-4, 2003, : 2443 - 2447
  • [45] Measuring the user acceptance of a web-based nursing documentation system
    Liaskos, J
    Mantas, J
    METHODS OF INFORMATION IN MEDICINE, 2006, 45 (01) : 116 - 120
  • [46] A New Prediction Model Based on Web Access Behavior
    Ye, Haiqin
    Li, Huan
    Zhang, Ailing
    INTERNATIONAL JOURNAL OF GRID AND DISTRIBUTED COMPUTING, 2016, 9 (12): : 23 - 33
  • [47] Mining access patterns of Web active user based on tree structure
    Bei, Yi-Jun
    Chen, Gang
    Dong, Jin-Xiang
    Zhejiang Daxue Xuebao (Gongxue Ban)/Journal of Zhejiang University (Engineering Science), 2009, 43 (06): : 1005 - 1013
  • [48] Optimal algorithms for finding user access sessions from very large web logs
    Chen, ZX
    Fu, AWC
    Tong, FCH
    WORLD WIDE WEB-INTERNET AND WEB INFORMATION SYSTEMS, 2003, 6 (03): : 259 - 279
  • [49] Research of Matrix Clustering Algorithm Based on Web User Access Pattern
    Bao, Jian
    WEB INFORMATION SYSTEMS AND MINING, PT II, 2011, 6988 : 154 - 159
  • [50] Terminology issues in user access to Web-based medical information
    McCray, AT
    Loane, RF
    Browne, AC
    Bangalore, AK
    JOURNAL OF THE AMERICAN MEDICAL INFORMATICS ASSOCIATION, 1999, : 107 - 111