A detection and offense mechanism to defend against application layer DDoS attacks

  • Jie Yu*
  • , Zhoujun Li
  • , Huowang Chen
  • , Xiaoming Chen
  • *Corresponding author for this work

Research output: Contribution to conferencePaperpeer-review

Abstract

Application layer DDoS attacks, which are legitimate in packets and protocols, gradually become a pressing problem for commerce, politics and military. We build an attack model and characterize layer-7 attacks into three classes: session flooding attacks, request flooding attacks and asymmetric attacks. We proposed a mechanism named as DOW (Defense and Offense Wall), which defends against layer-7 attacks using combination of detection technology and currency technology. An anomaly dete-ction method based on K-means clustering is introduced to detect and filter request flooding attacks and asymmetric attacks. To defend against session-flooding attacks, we propose an encoura-gement model that uses client's session rate as currency. Dete-ction model drops suspicious sessions, while currency model encourages more legitimate sessions. By collaboration of these two models, normal clients could gain higher service rate and lower delay of response time.

Original languageEnglish
DOIs
StatePublished - 2007
Event3rd International Conference on Networking and Services, ICNS 2007 - Athens, Greece
Duration: 19 Jun 200725 Jun 2007

Conference

Conference3rd International Conference on Networking and Services, ICNS 2007
Country/TerritoryGreece
CityAthens
Period19/06/0725/06/07

Keywords

  • Currency
  • DDoS attacks
  • Detection
  • Encouragement
  • K-means

Fingerprint

Dive into the research topics of 'A detection and offense mechanism to defend against application layer DDoS attacks'. Together they form a unique fingerprint.

Cite this