首页 | 本学科首页   官方微博 | 高级检索  
     

基于Web行为轨迹的应用层DDoS攻击防御模型
引用本文:刘泽宇,夏阳,张义龙,任远. 基于Web行为轨迹的应用层DDoS攻击防御模型[J]. 计算机应用, 2017, 37(1): 128-133. DOI: 10.11772/j.issn.1001-9081.2017.01.0128
作者姓名:刘泽宇  夏阳  张义龙  任远
作者单位:中国矿业大学 计算机科学与技术学院, 江苏 徐州 221116
摘    要:为了有效防御应用层分布式拒绝服务攻击(DDoS),定义了一种搭建在Web应用服务器上的基于Web行为轨迹的防御模型。把用户的访问行为抽象为Web行为轨迹,根据攻击请求的生成方式与用户访问Web页面的行为特征,定义了四种异常因素,分别为访问依赖异常、行为速率异常、轨迹重复异常、轨迹偏离异常。采用行为轨迹化简算法简化行为轨迹的计算,然后计算用户正常访问网站时和攻击访问时产生的异常因素的偏离值,来检测针对Web网站的分布式拒绝服务攻击,在检测出某用户产生攻击请求时,防御模型禁止该用户访问来防御DDoS。实验采用真实数据当作训练集,在模拟不同种类攻击请求下,防御模型短时间识别出攻击并且采取防御机制抵制。实验结果表明,Web行为轨迹的防御模型能够有效防御针对Web网站的分布式拒绝服务攻击。

关 键 词:分布式拒绝服务攻击  应用层  Web行为轨迹  攻击防御  
收稿时间:2016-07-26
修稿时间:2016-08-08

Application-layer DDoS defense model based on Web behavior trajectory
LIU Zeyu,XIA Yang,ZHANG Yilong,REN Yuan. Application-layer DDoS defense model based on Web behavior trajectory[J]. Journal of Computer Applications, 2017, 37(1): 128-133. DOI: 10.11772/j.issn.1001-9081.2017.01.0128
Authors:LIU Zeyu  XIA Yang  ZHANG Yilong  REN Yuan
Affiliation:College of Computer Science and Technology, China University of Mining and Technology, Xuzhou Jiangsu 221116, China
Abstract:To defense application-layer Distributed Denial of Service (DDoS) built on the normal network layer, a defense model based on Web behavior trajectory in the Web application server was constructed. User's access behavior was abstracted into Web behavior trajectory, and according to the generation approach about attack request as well as behavior characteristics of user access to Web pages, four kinds of suspicion were defined, including access dependency suspicion, behavior rate suspicion, trajectory similarity suspicion, and trajectory deviation suspicion. The deviation values between normal sessions and attack sessions were calculated to detect the application-layer DDoS to a specific website. The defense model prohibited the user access from DDoS when detecting the attack request generated by the user. In the experiment, real data was acted as the training set. Then, through simulating different kinds of attack request, the defense model could identify the attack request and take the defense mechanism against the attack. The experimental results demonstrate that the model can detect and defense the application-layer DDoS to a specific website.
Keywords:Distributed Denial of Service (DDoS)   application-layer   Web behavior trajectory   attack defence
点击此处可从《计算机应用》浏览原始摘要信息
点击此处可从《计算机应用》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号