Detecting Shrew HTTP Flood Attacks for Flash Crowds

  • Authors:
  • Yi Xie;Shun-Zheng Yu

  • Affiliations:
  • Department of Electrical and Communication Engineering Sun Yat-Sen University, Guangzhou 510275, P.R. China;Department of Electrical and Communication Engineering Sun Yat-Sen University, Guangzhou 510275, P.R. China

  • Venue:
  • ICCS '07 Proceedings of the 7th international conference on Computational Science, Part I: ICCS 2007
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

Countering network attacks is becoming ever more challenging. Web-based vulnerabilities represent a substantial portion of the security exposures of computer networks. In order to detect a new Web-based assault named shrew Distributed Denial of Service attacks based on HTTP flood, Principle Component Analysis and Independent Component Analysis are applied to abstract the multivariate observation vector. A novel anomaly detector based on hidden semi-Markov model is proposed. Experiment results based on real traffic trace and emulated attacks show, the scheme can be used effectively to implement the detection of the shrew HTTP flood attacks embedded in the normal flash crowd of large-scale Website; and the detection is not dependent on the intensity of attack traffic.