z-logo
open-access-imgOpen Access
Group Testing Based Detection of Web Service DDoS Attackers
Author(s) -
Dalia Nashat,
Xiaohong Jiang,
Michitaka Kameyama
Publication year - 2010
Publication title -
ieice transactions on communications
Language(s) - English
Resource type - Journals
SCImago Journal Rank - 0.211
H-Index - 56
eISSN - 1745-1345
pISSN - 0916-8516
DOI - 10.1587/transcom.e93.b.1113
Subject(s) - computer science , denial of service attack , computer security , application layer ddos attack , trace (psycholinguistics) , network packet , computer network , overhead (engineering) , bandwidth (computing) , the internet , world wide web , operating system , linguistics , philosophy
The Distributed Denial of Service attack (DDoS) is one of the major threats to network security that exhausts network bandwidth and resources. Recently, an efficient approach Live Baiting was proposed for detecting the identities of DDoS attackers in web service using low state overhead without requiring either the models of legitimate requests nor anomalous behavior. However, Live Baiting has two limitations. First, the detection algorithm adopted in Live Baiting starts with a suspects list containing all clients, which leads to a high false positive probability especially for large web service with a huge number of clients. Second, Live Baiting adopts a fixed threshold based on the expected number of requests in each bucket during the detection interval without the consideration of daily and weekly traffic variations. In order to address the above limitations, we first distinguish the clients activities (Active and Non-Active clients during the detection interval) in the detection process and then further propose a new adaptive threshold based on the Change Point Detection method, such that we can improve the false positive probability and avoid the dependence of detection on sites and access patterns. Extensive trace-driven simulation has been conducted on real Web trace to demonstrate the detection efficiency of the proposed scheme in comparison with the Live Baiting detection scheme.

The content you want is available to Zendy users.

Already have an account? Click here to sign in.
Having issues? You can contact us here
Accelerating Research

Address

John Eccles House
Robert Robinson Avenue,
Oxford Science Park, Oxford
OX4 4GP, United Kingdom