The Experts below are selected from a list of 4908 Experts worldwide ranked by ideXlab platform
Iwao Sasase - One of the best experts on this subject based on the ideXlab platform.
-
traceroute based target link Flooding Attack detection scheme by analyzing hop count to the destination
Asia-Pacific Conference on Communications, 2017Co-Authors: Kei Sakuma, Hiromu Asahina, Shuichiro Haruta, Iwao SasaseAbstract:Recently, the detection of target link Flooding Attack which is a new type of DDoS (Distributed Denial of Service) is required. Target link Flooding Attack is used for disconnecting a specific area from the Internet. It is more difficult to detect and mitigate this Attack than legacy DDoS since Attacking flows do not reach the target region. Among several schemes for target link Flooding Attack, the scheme focusing on traceroute is gathering attention. The idea behind that is the Attacker needs to send traceroute to investigate the topology around targeted region before Attack starts. That scheme detects the Attack by finding rapid increase of traceroute. However, it cannot work when Attacker's traceroute ratio is low. In this paper, we propose traceroute-based target link Flooding Attack detection scheme by analyzing hop count to the destination. Since the Attacker must choose the link flooded to disconnect the target area, the destinations of Attacker's traceroutes are concentrated within several hops from the target link while legitimate user's ones are distributed uniformly. By analyzing the number of traceroutes as per hop counts, the change can be emphasized and the Attack symptom might be more easily captured. By computer simulations, we first prove the above hypotheses and show that our scheme has more robustness compared with the conventional scheme.
-
fast target link Flooding Attack detection scheme by analyzing traceroute packets flow
International Workshop on Information Forensics and Security, 2015Co-Authors: Takayuki Hirayama, Kentaroh Toyoda, Iwao SasaseAbstract:Recently, a botnet based DDoS (Distributed Denial of Service) Attack, called target link Flooding Attack, has been reported that cuts off specific links over the Internet and disconnects a specific region from other regions. Detecting or mitigating the target link Flooding Attack is more difficult than legacy DDoS Attack techniques, since Attacking flows do not reach the target region. Although many mitigation schemes are proposed, they detect the Attack after it occurs. In this paper, we propose a fast target link Flooding Attack detection scheme by leveraging the fact that the traceroute packets are increased before the Attack caused by the Attacker's reconnaissance. Moreover, by analyzing the characteristic of the target link Flooding Attack that the number of traceroute packets simultaneously increases in various regions over the network, we propose a detection scheme with multiple detection servers to eliminate false alarms caused by sudden increase of traceroute packets sent by legitimate users. We show the effectiveness of our scheme by computer simulations.
Chimin Zhou - One of the best experts on this subject based on the ideXlab platform.
-
APCC - HTTP-sCAN: Detecting HTTP-Flooding Attack by modeling multi-features of web browsing behavior from noisy dataset
2013 19th Asia-Pacific Conference on Communications (APCC), 2013Co-Authors: Jin Wang, Xiaolong Yang, Keping Long, Min Zhang, Chimin ZhouAbstract:HTTP-Flooding Attack disables the victimized Web server by sending a large number of HTTP Get requests. Recent research tends to detect the Attacks with the anomaly-based approaches, which detect the HTTP-Flooding by modeling the behavior of normal Web users. However, most of the existing anomaly-based detection approaches usually cannot filter the Web crawling traces of the unknown search bots mixed in the normal Web browsing logs. These Web-crawling traces can bias the detection model in the training phase, thus further influencing the performance of the anomaly-based detection schemes. This paper proposes a novel anomaly-based HTTP-Flooding detection scheme (HTTP-sCAN), which can eliminate the influence of the Web-crawling traces with the cluster algorithm. The simulation results show that HTTP-sCAN is immune to the interferences of unknown search sessions, and can detect all HTTP-Flooding Attacks.
-
http scan detecting http Flooding Attack by modeling multi features of web browsing behavior from noisy dataset
Asia-Pacific Conference on Communications, 2013Co-Authors: Jin Wang, Xiaolong Yang, Keping Long, Min Zhang, Chimin ZhouAbstract:HTTP-Flooding Attack disables the victimized Web server by sending a large number of HTTP Get requests. Recent research tends to detect the Attacks with the anomaly-based approaches, which detect the HTTP-Flooding by modeling the behavior of normal Web users. However, most of the existing anomaly-based detection approaches usually cannot filter the Web crawling traces of the unknown search bots mixed in the normal Web browsing logs. These Web-crawling traces can bias the detection model in the training phase, thus further influencing the performance of the anomaly-based detection schemes. This paper proposes a novel anomaly-based HTTP-Flooding detection scheme (HTTP-sCAN), which can eliminate the influence of the Web-crawling traces with the cluster algorithm. The simulation results show that HTTP-sCAN is immune to the interferences of unknown search sessions, and can detect all HTTP-Flooding Attacks.
Jin Wang - One of the best experts on this subject based on the ideXlab platform.
-
HTTP-sCAN: Detecting HTTP-Flooding Attack by modeling multi-features of web browsing behavior from noisy web-logs
China Communications, 2015Co-Authors: Jin Wang, Keping Long, Xiaolong Yang, Min Zhang, Jie XuAbstract:HTTP-Flooding Attack disables the victimized web server by sending a large number of HTTP Get requests. Recent research tends to detect HTTP-Flooding with the anomaly-based approaches, which detect the HTTP-Flooding by modeling the behavior of normal web surfers. However, most of the existing anomaly-based detection approaches usually cannot filter the web-crawling traces from unknown searching bots mixed in normal web browsing logs. These web-crawling traces can bias the base-line profile of anomaly-based schemes in their training phase, and further degrade their detection performance. This paper proposes a novel web-crawling traces-tolerated method to build baseline profile, and designs a new anomaly-based HTTP-Flooding detection scheme (abbr. HTTP-sCAN). The simulation results show that HTTP-sCAN is immune to the interferences of unknown web-crawling traces, and can detect all HTTP-Flooding Attacks.
-
http soldier an http Flooding Attack detection scheme with the large deviation principle
Science in China Series F: Information Sciences, 2014Co-Authors: Jin Wang, Xiaolong Yang, Min Zhang, Keping LongAbstract:HTTP-Flooding Attack is a much stealthier distributed denial of service (DDoS) Attack, challenging the survivability of the web services seriously. Observing the web access behavior, we find that the surfing preference of normal users is much more consistent with the webpage popularity than that of malicious users. Based on this observation, this paper proposes a novel detection scheme for HTTP-Flooding (HTTP-SoLDiER). Specifically, HTTP-SoLDiER first quantifies the consistency between web users surfing preference and the webpage popularity with large-deviation principle. Then HTTP-SoLDiER distinguishes the malicious users from normal ones according to the large-deviation probability. In practice, the webpage popularity plays a key role in Attack detection of HTTP-SoLDiER. Due to the never-ending updating of the webpage content and the disturbance induced by Attackers, the webpage popularity often varies over time. Thus, it is critical for HTTP-SoLDiER to dynamically update the webpage popularity. We design a reversible exponentially weighted moving average (EWMA) algorithm to solve the problem. Finally, we evaluate the effectiveness of this scheme in terms of true positive (TP) and false positive (FP) probabilities with NS-3 simulations. The simulation results show that HTTP-SoLDiER can detect all random HTTP-Flooding Attackers and most of the perfect-knowledge HTTP-Flooding Attackers at little false positive.
-
APCC - HTTP-sCAN: Detecting HTTP-Flooding Attack by modeling multi-features of web browsing behavior from noisy dataset
2013 19th Asia-Pacific Conference on Communications (APCC), 2013Co-Authors: Jin Wang, Xiaolong Yang, Keping Long, Min Zhang, Chimin ZhouAbstract:HTTP-Flooding Attack disables the victimized Web server by sending a large number of HTTP Get requests. Recent research tends to detect the Attacks with the anomaly-based approaches, which detect the HTTP-Flooding by modeling the behavior of normal Web users. However, most of the existing anomaly-based detection approaches usually cannot filter the Web crawling traces of the unknown search bots mixed in the normal Web browsing logs. These Web-crawling traces can bias the detection model in the training phase, thus further influencing the performance of the anomaly-based detection schemes. This paper proposes a novel anomaly-based HTTP-Flooding detection scheme (HTTP-sCAN), which can eliminate the influence of the Web-crawling traces with the cluster algorithm. The simulation results show that HTTP-sCAN is immune to the interferences of unknown search sessions, and can detect all HTTP-Flooding Attacks.
-
http scan detecting http Flooding Attack by modeling multi features of web browsing behavior from noisy dataset
Asia-Pacific Conference on Communications, 2013Co-Authors: Jin Wang, Xiaolong Yang, Keping Long, Min Zhang, Chimin ZhouAbstract:HTTP-Flooding Attack disables the victimized Web server by sending a large number of HTTP Get requests. Recent research tends to detect the Attacks with the anomaly-based approaches, which detect the HTTP-Flooding by modeling the behavior of normal Web users. However, most of the existing anomaly-based detection approaches usually cannot filter the Web crawling traces of the unknown search bots mixed in the normal Web browsing logs. These Web-crawling traces can bias the detection model in the training phase, thus further influencing the performance of the anomaly-based detection schemes. This paper proposes a novel anomaly-based HTTP-Flooding detection scheme (HTTP-sCAN), which can eliminate the influence of the Web-crawling traces with the cluster algorithm. The simulation results show that HTTP-sCAN is immune to the interferences of unknown search sessions, and can detect all HTTP-Flooding Attacks.
Keping Long - One of the best experts on this subject based on the ideXlab platform.
-
HTTP-sCAN: Detecting HTTP-Flooding Attack by modeling multi-features of web browsing behavior from noisy web-logs
China Communications, 2015Co-Authors: Jin Wang, Keping Long, Xiaolong Yang, Min Zhang, Jie XuAbstract:HTTP-Flooding Attack disables the victimized web server by sending a large number of HTTP Get requests. Recent research tends to detect HTTP-Flooding with the anomaly-based approaches, which detect the HTTP-Flooding by modeling the behavior of normal web surfers. However, most of the existing anomaly-based detection approaches usually cannot filter the web-crawling traces from unknown searching bots mixed in normal web browsing logs. These web-crawling traces can bias the base-line profile of anomaly-based schemes in their training phase, and further degrade their detection performance. This paper proposes a novel web-crawling traces-tolerated method to build baseline profile, and designs a new anomaly-based HTTP-Flooding detection scheme (abbr. HTTP-sCAN). The simulation results show that HTTP-sCAN is immune to the interferences of unknown web-crawling traces, and can detect all HTTP-Flooding Attacks.
-
http soldier an http Flooding Attack detection scheme with the large deviation principle
Science in China Series F: Information Sciences, 2014Co-Authors: Jin Wang, Xiaolong Yang, Min Zhang, Keping LongAbstract:HTTP-Flooding Attack is a much stealthier distributed denial of service (DDoS) Attack, challenging the survivability of the web services seriously. Observing the web access behavior, we find that the surfing preference of normal users is much more consistent with the webpage popularity than that of malicious users. Based on this observation, this paper proposes a novel detection scheme for HTTP-Flooding (HTTP-SoLDiER). Specifically, HTTP-SoLDiER first quantifies the consistency between web users surfing preference and the webpage popularity with large-deviation principle. Then HTTP-SoLDiER distinguishes the malicious users from normal ones according to the large-deviation probability. In practice, the webpage popularity plays a key role in Attack detection of HTTP-SoLDiER. Due to the never-ending updating of the webpage content and the disturbance induced by Attackers, the webpage popularity often varies over time. Thus, it is critical for HTTP-SoLDiER to dynamically update the webpage popularity. We design a reversible exponentially weighted moving average (EWMA) algorithm to solve the problem. Finally, we evaluate the effectiveness of this scheme in terms of true positive (TP) and false positive (FP) probabilities with NS-3 simulations. The simulation results show that HTTP-SoLDiER can detect all random HTTP-Flooding Attackers and most of the perfect-knowledge HTTP-Flooding Attackers at little false positive.
-
APCC - HTTP-sCAN: Detecting HTTP-Flooding Attack by modeling multi-features of web browsing behavior from noisy dataset
2013 19th Asia-Pacific Conference on Communications (APCC), 2013Co-Authors: Jin Wang, Xiaolong Yang, Keping Long, Min Zhang, Chimin ZhouAbstract:HTTP-Flooding Attack disables the victimized Web server by sending a large number of HTTP Get requests. Recent research tends to detect the Attacks with the anomaly-based approaches, which detect the HTTP-Flooding by modeling the behavior of normal Web users. However, most of the existing anomaly-based detection approaches usually cannot filter the Web crawling traces of the unknown search bots mixed in the normal Web browsing logs. These Web-crawling traces can bias the detection model in the training phase, thus further influencing the performance of the anomaly-based detection schemes. This paper proposes a novel anomaly-based HTTP-Flooding detection scheme (HTTP-sCAN), which can eliminate the influence of the Web-crawling traces with the cluster algorithm. The simulation results show that HTTP-sCAN is immune to the interferences of unknown search sessions, and can detect all HTTP-Flooding Attacks.
-
http scan detecting http Flooding Attack by modeling multi features of web browsing behavior from noisy dataset
Asia-Pacific Conference on Communications, 2013Co-Authors: Jin Wang, Xiaolong Yang, Keping Long, Min Zhang, Chimin ZhouAbstract:HTTP-Flooding Attack disables the victimized Web server by sending a large number of HTTP Get requests. Recent research tends to detect the Attacks with the anomaly-based approaches, which detect the HTTP-Flooding by modeling the behavior of normal Web users. However, most of the existing anomaly-based detection approaches usually cannot filter the Web crawling traces of the unknown search bots mixed in the normal Web browsing logs. These Web-crawling traces can bias the detection model in the training phase, thus further influencing the performance of the anomaly-based detection schemes. This paper proposes a novel anomaly-based HTTP-Flooding detection scheme (HTTP-sCAN), which can eliminate the influence of the Web-crawling traces with the cluster algorithm. The simulation results show that HTTP-sCAN is immune to the interferences of unknown search sessions, and can detect all HTTP-Flooding Attacks.
Yang Xue-hua - One of the best experts on this subject based on the ideXlab platform.
-
An Efficient Prevention Model Against SIP Flooding Attack
Computer Engineering, 2013Co-Authors: Yang Xue-huaAbstract:By analyzing the principle,mode,characteristics of Denial of Service(DoS) Attack aiming at Session Initiation Protocol(SIP) and Flooding Attack faced by SIP network,this paper proposes a prevention model combining a dynamic threshold adjustment with real-time dynamic prevention for SIP Flooding Attack.It can dynamically adjust the threshold and detect SIP Flooding Attack through chi-square traffic judging mode and cumulative statistics mode,and can dynamically prevent IP-based SIP Flooding Attacks with IP defense model.Experimental result shows that the model can effectively detect and prevent the SIP Flooding Attack,and reduce the probability of SIP/IMS server being Attacked when SIP network is on the abnormity.