Impact of class distribution on the detection of slow HTTP DoS attacks using Big Data

被引:0
|
作者
Chad L. Calvert
Taghi M. Khoshgoftaar
机构
[1] Florida Atlantic University,
来源
关键词
Class imbalance; Slow HTTP DoS; Class imbalance; Big Data;
D O I
暂无
中图分类号
学科分类号
摘要
The integrity of modern network communications is constantly being challenged by more sophisticated intrusion techniques. Attackers are consistently shifting to stealthier and more complex forms of attacks in an attempt to bypass known mitigation strategies. In recent years, attackers have begun to focus their attack efforts on the application layer, allowing them to produce attacks that can exploit known issues within specific application protocols. Slow HTTP Denial of Service attacks are one such attack variant, which targets the HTTP protocol and can imitate legitimate user traffic in order to deny resources from a service. Successful mitigation of this attack type requires network analysts to evaluate large quantities of network traffic to identify and block intrusive traffic. The issue, is that the number of legitimate traffic instances can far outnumber the amount of attack instances, making detection problematic. Machine learning techniques can be used to aid in detection, but the large level of imbalance between normal (majority) and attack (minority) instances can lead to inaccurate detection results. In this work, we evaluate the use of data sampling to produce varying class distributions in order to counteract the effects of severely imbalanced Slow HTTP DoS big datasets. We also detail our process for collecting real-world representative Slow HTTP DoS attack traffic from a live network environment to create our datasets. Five class distributions are generated to evaluate the Slow HTTP DoS detection performance of eight machine learning techniques. Our results show that the optimal learner and class distribution combination is that of Random Forest with a 65:35 distribution ratio, obtaining an AUC value of 0.99904. Further, we determine through the use of significance testing, that the use of sampling techniques can significantly increase learner performance when detecting Slow HTTP DoS attack traffic.
引用
收藏
相关论文
共 50 条
  • [41] Detection and reconstruction of measurements against false data injection and DoS attacks in distribution system state estimation: A deep learning approach
    Raghuvamsi, Y.
    Teeparthi, Kiran
    MEASUREMENT, 2023, 210
  • [42] Impact of Memory DoS Attacks on Cloud Applications and Real-Time Detection Schemes
    Li, Zhuozhao
    Sen, Tanmoy
    Shen, Haiying
    Chuah, Mooi Choo
    2020 IEEE 40TH INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS (ICDCS), 2020, : 1191 - 1192
  • [43] Impact of Memory DoS Attacks on Cloud Applications and Real-Time Detection Schemes
    Li, Zhuozhao
    Sen, Tanmoy
    Shen, Haiying
    Chuah, Mooi Choo
    PROCEEDINGS OF THE 49TH INTERNATIONAL CONFERENCE ON PARALLEL PROCESSING, ICPP 2020, 2020,
  • [44] SliceSecure: Impact and Detection of DoS/DDoS Attacks on 5G Network Slices
    Khan, Md Sajid
    Farzaneh, Behnam
    Shahriar, Nashid
    Saha, Niloy
    Boutaba, Raouf
    2022 IEEE FUTURE NETWORKS WORLD FORUM, FNWF, 2022, : 639 - 642
  • [45] Detecting DoS and DDoS Attacks by using an Intrusion Detection and Remote Prevention System
    Leu, Fang-Yie
    Li, Zhi-Yang
    FIFTH INTERNATIONAL CONFERENCE ON INFORMATION ASSURANCE AND SECURITY, VOL 2, PROCEEDINGS, 2009, : 251 - 254
  • [46] Big Data-Driven Detection of False Data Injection Attacks in Smart Meters
    Unal, Fatih
    Almalaq, Abdulaziz
    Ekici, Sami
    Glauner, Patrick
    IEEE ACCESS, 2021, 9 (09): : 144313 - 144326
  • [47] SPGDAD: Slow HTTP-Get denial of service attack detection using ontology
    Haddadi, Mohamed
    Khiat, Abdelhamid
    Bouaoud, Hadil
    Djehiche, Hadjer
    INFORMATION SECURITY JOURNAL, 2025, 34 (01): : 79 - 87
  • [48] A Proposed DoS Detection Scheme for Mitigating DoS Attack Using Data Mining Techniques
    Djanie, Kotey Seth
    Tutu, Tchao Eric
    Dzisi, Gadze James
    COMPUTERS, 2019, 8 (04)
  • [49] Detection of DoS attacks in cloud networks using intelligent rule based classification system
    Rajendran, Rakesh
    Kumar, S. V. N. Santhosh
    Palanichamy, Yogesh
    Arputharaj, Kannan
    CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2019, 22 (Suppl 1): : 423 - 434
  • [50] Detection of DoS Attacks Using ARFIMA Modeling of GOOSE Communication in IEC 61850 Substations
    Elbez, Ghada
    Keller, Hubert B.
    Bohara, Atul
    Nahrstedt, Klara
    Hagenmeyer, Veit
    ENERGIES, 2020, 13 (19)