Title : 
Web DDoS Detection Schemes Based on Measuring User´s Access Behavior with Large Deviation
         
        
            Author : 
Wang, Jin ; Yang, Xiaolong ; Long, Keping
         
        
            Author_Institution : 
Res. Center for Opt. Internet & Mobile Inf. Network, Univ. of Electron. Sci. & Technol. of China, Chengdu, China
         
        
        
        
        
        
            Abstract : 
Distributed denial-of-service (DDoS) attack seriously threatens the survivability of web services. It attempts to exhaust a server\´s resources (e.g., I/O bandwidth, CPU, and memory resources) to the extent that no resource is available for requests from legitimate users. Recently, some attackers launch web DDoS attack from the application layer (i.e., web app-DDoS), which can evade most of the existing detection approaches that mainly focused on Bandwidth-Flooding DDoS and TCP SYN-Flooding DDoS. This paper discusses the detection of web app-DDoS, and present two different models to characterize user\´s web access behavior, i.e., click-ratio based model and Markov process based model. With these characterizations as reference, we adopt large deviation theory to estimate the probability that each ongoing user\´s access behavior is "consistent" with the corresponding reference characterization, and propose two different detection schemes, LD-IID and LD-MP, respectively. We also validate our schemes with simulations, and the simulation results show that LD-IID can detect attackers accurately, yet LD-MP has high false negatives.
         
        
            Keywords : 
Markov processes; Web services; computer network security; probability; reliability; transport protocols; LD-IID; LD-MP; Markov process; TCP SYN flooding; Web DDoS detection; Web services; bandwidth flooding; distributed denial of service attack; probability estimation; survivability; users access behavior; Computer crime; Markov processes; Monitoring; Vectors; Web servers;
         
        
        
        
            Conference_Titel : 
Global Telecommunications Conference (GLOBECOM 2011), 2011 IEEE
         
        
            Conference_Location : 
Houston, TX, USA
         
        
        
            Print_ISBN : 
978-1-4244-9266-4
         
        
            Electronic_ISBN : 
1930-529X
         
        
        
            DOI : 
10.1109/GLOCOM.2011.6133798