Denial-of-service mitigation for internet services

A Kalliola, T Aura, S Šćepanović - … 2014, Tromsø, Norway, October 15-17 …, 2014 - Springer
A Kalliola, T Aura, S Šćepanović
Secure IT Systems: 19th Nordic Conference, NordSec 2014, Tromsø, Norway …, 2014Springer
Denial-of-service attacks present a serious threat to the availability of online services.
Distributed attackers, ie botnets, are capable of exhausting the server capacity with
legitimate-looking requests. Such attacks are difficult to defend against using traditional
filtering mechanisms. We propose a machine learning and filtering system that forms a
profile of normal client behavior based on normal traffic features and, during an attack,
optimizes capacity allocation for legitimate clients based on the profile. The proposed …
Abstract
Denial-of-service attacks present a serious threat to the availability of online services. Distributed attackers, i.e. botnets, are capable of exhausting the server capacity with legitimate-looking requests. Such attacks are difficult to defend against using traditional filtering mechanisms. We propose a machine learning and filtering system that forms a profile of normal client behavior based on normal traffic features and, during an attack, optimizes capacity allocation for legitimate clients based on the profile. The proposed defense mechanism is evaluated using simulations based on real-life server usage patterns. The simulations indicate that the mechanism is capable of mitigating an overwhelming server capacity exhaustion DDoS attack. During attacks where a botnet floods a server with legitimate-looking requests, over 80 percent of the legitimate clients are still served, even on servers that are heavily loaded to begin with. An implementation of the mechanism is tested using synthetic HTTP attack traffic, also with encouraging results.
Springer
Showing the best result for this search. See all results