首页 | 本学科首页   官方微博 | 高级检索  
     


Defense techniques for low-rate DoS attacks against application servers
Authors:Gabriel Maciá-Fernández  Rafael A Rodríguez-Gómez  Jesús E Díaz-Verdejo
Affiliation:1. Department of Mechanical Engineering, West Virginia University Institute of Technology, 405 Fayette Pike, Montgomery, WV 25136-2436, USA;2. Department of Mechanical and Industrial Engineering, Ryerson University, 350 Victoria Street, Toronto, Ontario M5B 2K3, Canada;1. Department of Computer Science & Engineering, Daffodil International University, Dhaka, Bangladesh;2. College of Engineering and Computer Science, Abu Dhabi University, United Arab Emirates;3. School of Engineering, Monash University Malaysia, Jalan Lagoon Selatan, Bandar Sunway, 46150, Selangor Darul Ehsan, Malaysia
Abstract:Low-rate denial of service (DoS) attacks have recently emerged as new strategies for denying networking services. Such attacks are capable of discovering vulnerabilities in protocols or applications behavior to carry out a DoS with low-rate traffic. In this paper, we focus on a specific attack: the low-rate DoS attack against application servers, and address the task of finding an effective defense against this attack.Different approaches are explored and four alternatives to defeat these attacks are suggested. The techniques proposed are based on modifying the way in which an application server accepts incoming requests. They focus on protective measures aimed at (i) preventing an attacker from capturing all the positions in the incoming queues of applications, and (ii) randomizing the server operation to eliminate possible vulnerabilities due to predictable behaviors.We extensively describe the suggested techniques, discussing the benefits and drawbacks for each under two criteria: the attack efficiency reduction obtained, and the impact on the normal operation of the server. We evaluate the proposed solutions in a both a simulated and a real environment, and provide guidelines for their implementation in a production system.
Keywords:
本文献已被 ScienceDirect 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号