• DocumentCode
    28339
  • Title

    Resisting Web Proxy-Based HTTP Attacks by Temporal and Spatial Locality Behavior

  • Author

    Yi Xie ; Tang, Song ; Xiang, Yingmeng ; Hu, Jiankun

  • Author_Institution
    Sch. of Inf. Sci. & Technol., Sun YatSen Univ., Guangzhou, China
  • Volume
    24
  • Issue
    7
  • fYear
    2013
  • fDate
    Jul-13
  • Firstpage
    1401
  • Lastpage
    1410
  • Abstract
    A novel server-side defense scheme is proposed to resist the Web proxy-based distributed denial of service attack. The approach utilizes the temporal and spatial locality to extract the behavior features of the proxy-to-server traffic, which makes the scheme independent of the traffic intensity and frequently varying Web contents. A nonlinear mapping function is introduced to protect weak signals from the interference of infrequent large values. Then, a new hidden semi-Markov model parameterized by Gaussian-mixture and Gamma distributions is proposed to describe the time-varying traffic behavior of Web proxies. The new method reduces the number of parameters to be estimated, and can characterize the dynamic evolution of the proxy-to-server traffic rather than the static statistics. Two diagnosis approaches at different scales are introduced to meet the requirement of both fine-grained and coarse-grained detection. Soft control is a novel attack response method proposed in this work. It converts a suspicious traffic into a relatively normal one by behavior reshaping rather than rudely discarding. This measure can protect the quality of services of legitimate users. The experiments confirm the effectiveness of the proposed scheme.
  • Keywords
    Gaussian processes; Web sites; computer network security; content management; gamma distribution; hidden Markov models; hypermedia; interference (signal); network servers; nonlinear functions; quality of service; signal detection; telecommunication traffic; Gaussian mixture model; Web content; Web proxy-based HTTP attack resistance; coarse grained detection; distributed denial of service; dynamic evolution; fine grained detection; gamma distribution; hidden semiMarkov model; interference suppression; nonlinear mapping function; proxy-to-server traffic; quality of service; server side defense scheme; signal protection; spatial locality behavior extraction; static statistics; temporal locality behavior extraction; time-varying traffic behavior; traffic intensity; Computer crime; Educational institutions; Electronic mail; Hidden Markov models; Indexes; Servers; Stochastic processes; Traffic analysis; attack detection; attack response; distributed denial of service attack; traffic modeling;
  • fLanguage
    English
  • Journal_Title
    Parallel and Distributed Systems, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1045-9219
  • Type

    jour

  • DOI
    10.1109/TPDS.2012.232
  • Filename
    6255740