节点文献

基于Web行为轨迹的应用层DDoS攻击防御模型

Application-layer DDoS defense model based on Web behavior trajectory

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 刘泽宇夏阳张义龙任远

【Author】 LIU Zeyu;XIA Yang;ZHANG Yilong;REN Yuan;College of Computer Science and Technology,China University of Mining and Technology;

【机构】 中国矿业大学计算机科学与技术学院

【摘要】 为了有效防御应用层分布式拒绝服务攻击(DDoS),定义了一种搭建在Web应用服务器上的基于Web行为轨迹的防御模型。把用户的访问行为抽象为Web行为轨迹,根据攻击请求的生成方式与用户访问Web页面的行为特征,定义了四种异常因素,分别为访问依赖异常、行为速率异常、轨迹重复异常、轨迹偏离异常。采用行为轨迹化简算法简化行为轨迹的计算,然后计算用户正常访问网站时和攻击访问时产生的异常因素的偏离值,来检测针对Web网站的分布式拒绝服务攻击,在检测出某用户产生攻击请求时,防御模型禁止该用户访问来防御DDoS。实验采用真实数据当作训练集,在模拟不同种类攻击请求下,防御模型短时间识别出攻击并且采取防御机制抵制。实验结果表明,Web行为轨迹的防御模型能够有效防御针对Web网站的分布式拒绝服务攻击。

【Abstract】 To defense application-layer Distributed Denial of Service( DDo S) built on the normal network layer,a defense model based on Web behavior trajectory in the Web application server was constructed. User’s access behavior was abstracted into Web behavior trajectory,and according to the generation approach about attack request as well as behavior characteristics of user access to Web pages,four kinds of suspicion were defined,including access dependency suspicion,behavior rate suspicion,trajectory similarity suspicion,and trajectory deviation suspicion. The deviation values between normal sessions and attack sessions were calculated to detect the application-layer DDo S to a specific website. The defense model prohibited the user access from DDo S when detecting the attack request generated by the user. In the experiment,real data was acted as the training set. Then,through simulating different kinds of attack request,the defense model could identify the attack request and take the defense mechanism against the attack. The experimental results demonstrate that the model can detect and defense the application-layer DDo S to a specific website.

  • 【文献出处】 计算机应用 ,Journal of Computer Applications , 编辑部邮箱 ,2017年01期
  • 【分类号】TP393.08
  • 【被引频次】16
  • 【下载频次】269
节点文献中: 

本文链接的文献网络图示:

本文的引文网络