Application Layer Real-time Proactive Defense System Based on Application Layer Protocol Analysis

XIE Bai-Lin,YU Shun-Zheng
DOI: https://doi.org/10.3724/sp.j.1016.2011.00452
2011-01-01
Abstract:Proactive defense is a prevalent topic in current research field of network security.Existing proactive defense techniques mainly detect attacks from network layer and transport layer.Since most new attacks are based on application layer protocols and don't present significant difference in network traffic,it is difficult for existing proactive defense techniques to effectively detect such application layer attacks without special techniques.Therefore,the research on proactive defense of application layer becomes very important.This paper presents a risk real-time evaluation method for application layer based on hidden semi-Markov model.This method evaluates the application layer risk by analyzing network traffic.Based on this risk evaluation method and application layer protocol analysis,this paper presents a real-time proactive defense system for application layer.When user's behavior is at risk,the system queues the user's packets according to the risk indicator.By this means,the proposed system can automatically restrict each user's anomalous behavior,and achieve the application layer proactive defense.The final experiment results validate the performance of the system.
What problem does this paper attempt to address?