Low-Rate Application-Layer DDoS Attacks Detection by Principal Component Analysis (PCA) through User Browsing Behavior

Article Preview

Abstract:

Application-layer distributed denials of service (DDoS) attacks are becoming ever more challenging to internet service security, since firewall and intrusion detection system work on network layer while these attacks are launched on application layer. In contrast to prior work focusing on detection of high-rate DDoS attacks at static web sites, we propose a novel approach to detect low-rate application-layer DDoS attacks at dynamic web sites. A feature matrix is introduced to characterize user browsing behavior. Principal component analysis (PCA) is applied to profile the user browsing behavior pattern. Outliers from this pattern are used to identify anomaly users. Experiments are conducted to validate our approach. Experimental results show that our approach is accurate to detect low-rate application-layer DDoS attacks.

You might also be interested in these eBooks

Info:

Periodical:

Pages:

1945-1948

Citation:

Online since:

September 2013

Export:

Price:

Permissions CCC:

Permissions PLS:

Сopyright:

© 2013 Trans Tech Publications Ltd. All Rights Reserved

Share:

Citation:

[1] Xie, Y. and S.Z. Yu: Ieee-Acm Transactions on Networking, 2009. 17(1): pp.15-25.

Google Scholar

[2] Xie, Y. and S.Z. Yu: Ieee-Acm Transactions on Networking, 2009. 17(1): pp.54-65.

Google Scholar

[3] Lee, S., G. Kim, and S. Kim: Eurasip Journal on Wireless Communications and Networking, 2011. (1): pp.1-9.

Google Scholar

[4] Shlens, Jonathon.: A tutorial on principal component analysis, Systems Neurobiology Laboratory, University of California at San Diego (2005).

Google Scholar

[5] Information on http: / jmeter. apache. org.

Google Scholar