A Model for Detecting Application Layer Flooding Attacks

XIE Yi,YU Shun-Zheng
DOI: https://doi.org/10.3969/j.issn.1002-137X.2007.08.029
2007-01-01
Computer Science
Abstract:Distributed Denial of Service(DDoS)attacks are typically carried out at the network layer.However,there is evidence to suggest that application layer DDoS attacks can be more effective than the traditional ones.A sophisticated attack using legitimate application layer HTTP requests from legitimately connected network machines to overwhelm Web server is discussed.A counter-mechanism based on Web user browsing behavior is proposed to protect the servers from these attacks.In contrast to prior works,Hidden semi-Markov Model is explored to describe the browsing behaviors of Web users and to implement the anomaly detection for the application layer flooding attacks.By conducting an experiment with a real traffic data,the model shows that it is effective in measuring the user behaviors and detecting the application layer flooding attacks.
What problem does this paper attempt to address?