2016
DOI: 10.3906/elk-1308-188
|View full text |Cite
|
Sign up to set email alerts
|

Behavior-based detection of application layer distributed denial of service attacks during flash events

Abstract: Distributed denial of service (DDoS) attacks are ever threatening to the developers and users of the Internet. DDoS attacks targeted at the application layer are especially difficult to be detected since they mimic the legitimate users' requests. The situation becomes more serious when they occur during flash events. A more sophisticated algorithm is required to detect such attacks during a flash crowd. A few existing works make use of flow similarity for differentiating flash crowds and DDoS, but flow charact… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
14
0

Year Published

2017
2017
2020
2020

Publication Types

Select...
5
4

Relationship

0
9

Authors

Journals

citations
Cited by 38 publications
(14 citation statements)
references
References 20 publications
(35 reference statements)
0
14
0
Order By: Relevance
“…Kurt et al's study was about detecting SIP-based DDoS attacks [9]. Saravanan et al worked on a system for the detection of application layer DDoS attacks [10]. In addition, several studies have been conducted in attack detection and mitigation techniques on fog [11,12] and cloud computing [13,14].…”
Section: Background and Related Workmentioning
confidence: 99%
“…Kurt et al's study was about detecting SIP-based DDoS attacks [9]. Saravanan et al worked on a system for the detection of application layer DDoS attacks [10]. In addition, several studies have been conducted in attack detection and mitigation techniques on fog [11,12] and cloud computing [13,14].…”
Section: Background and Related Workmentioning
confidence: 99%
“…In this method early detect the DDoS attacks. The authors [7] have proposed a concept for detecting DDoS attack and the Flash events based on the 3 key parameters, flow similarity, pages referred, and client legitimacy. The result of proposed method achieves reduced false positive and false negative.…”
Section: T Subburaj K Suthendranmentioning
confidence: 99%
“…DDoS attack at the application layer focuses on sending large amounts of GET request to a web server, and detection of this attack becomes more complicated when flash crowd is implemented. A flash crowd refers to the increasing number of legitimate HTTP GETrequest received by a web server due to several events, such as result announcements, new product launches, and breaking news [14]. Iyengar and Ganapathy [15] mentioned that flash crowds occur when plenty of authentic concurrent incoming connections are received by a web server in a short period of time.…”
Section: Introductionmentioning
confidence: 99%