24
views
0
recommends
+1 Recommend
0 collections
    0
    shares
      • Record: found
      • Abstract: found
      • Article: found
      Is Open Access

      Recent Analysis of Forged Request Headers Constituted by HTTP DDoS

      research-article

      Read this article at

      Bookmark
          There is no author summary for this article yet. Authors can add summaries to their articles on ScienceOpen to make them more accessible to a non-specialist audience.

          Abstract

          Application Layer Distributed Denial of Service (DDoS) attacks are very challenging to detect. The shortfall at the application layer allows formation of HTTP DDoS as the request headers are not compulsory to be attached in an HTTP request. Furthermore, the header is editable, thus providing an attacker with the advantage to execute HTTP DDoS as it contains almost similar request header that can emulate a genuine client request. To the best of the authors’ knowledge, there are no recent studies that provide forged request headers pattern with the execution of the current HTTP DDoS attack scripts. Besides that, the current dataset for HTTP DDoS is not publicly available which leads to complexity for researchers to disclose false headers, causing them to rely on old dataset rather than more current attack patterns. Hence, this study conducted an analysis to disclose forged request headers patterns created by HTTP DDoS. The results of this study successfully disclose eight forged request headers patterns constituted by HTTP DDoS. The analysis was executed by using actual machines and eight real attack scripts which are capable of overwhelming a web server in a minimal duration. The request headers patterns were explained supported by a critical analysis to provide the outcome of this paper.

          Related collections

          Most cited references56

          • Record: found
          • Abstract: not found
          • Article: not found

          A Survey of Defense Mechanisms Against Distributed Denial of Service (DDoS) Flooding Attacks

            Bookmark
            • Record: found
            • Abstract: not found
            • Article: not found

            Distributed denial of service (DDoS) resilience in cloud: Review and conceptual cloud DDoS mitigation framework

              Bookmark
              • Record: found
              • Abstract: found
              • Article: found
              Is Open Access

              A DDoS Attack Detection Method Based on SVM in Software Defined Network

              The detection of DDoS attacks is an important topic in the field of network security. The occurrence of software defined network (SDN) (Zhang et al., 2018) brings up some novel methods to this topic in which some deep learning algorithm is adopted to model the attack behavior based on collecting from the SDN controller. However, the existing methods such as neural network algorithm are not practical enough to be applied. In this paper, the SDN environment by mininet and floodlight (Ning et al., 2014) simulation platform is constructed, 6-tuple characteristic values of the switch flow table is extracted, and then DDoS attack model is built by combining the SVM classification algorithms. The experiments show that average accuracy rate of our method is 95.24 % with a small amount of flow collecting. Our work is of good value for the detection of DDoS attack in SDN.
                Bookmark

                Author and article information

                Journal
                Sensors (Basel)
                Sensors (Basel)
                sensors
                Sensors (Basel, Switzerland)
                MDPI
                1424-8220
                08 July 2020
                July 2020
                : 20
                : 14
                : 3820
                Affiliations
                Razak Faculty of Technology and Informatics, Universiti Teknologi Malaysia (UTM), Kuala Lumpur 54100, Malaysia; saifuladli@ 123456utm.my (S.A.I.); mshahidan@ 123456utm.my (M.S.A.); mdnazri@ 123456utm.my (N.K.); azriazmi@ 123456utm.my (A.A.); othmanyusop@ 123456utm.my (O.M.Y.)
                Author notes
                [* ]Correspondence: afastars@ 123456gmail.com
                Author information
                https://orcid.org/0000-0001-7644-6533
                https://orcid.org/0000-0002-9299-5652
                Article
                sensors-20-03820
                10.3390/s20143820
                7411862
                32650597
                fa57868c-45db-4359-b652-ad7bd44cc749
                © 2020 by the authors.

                Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license ( http://creativecommons.org/licenses/by/4.0/).

                History
                : 18 May 2020
                : 23 June 2020
                Categories
                Article

                Biomedical engineering
                ddos,http ddos,get headers
                Biomedical engineering
                ddos, http ddos, get headers

                Comments

                Comment on this article