DC Field | Value | Language |
---|---|---|
dc.contributor.author | Lee, Sang-Jae | ko |
dc.contributor.author | Kim, Gi-Sung | ko |
dc.contributor.author | Kim, Se-Hun | ko |
dc.date.accessioned | 2013-03-12T19:14:03Z | - |
dc.date.available | 2013-03-12T19:14:03Z | - |
dc.date.created | 2012-06-19 | - |
dc.date.created | 2012-06-19 | - |
dc.date.issued | 2011-08 | - |
dc.identifier.citation | EURASIP JOURNAL ON WIRELESS COMMUNICATIONS AND NETWORKING, v.2011, no.50 | - |
dc.identifier.issn | 1687-1499 | - |
dc.identifier.uri | http://hdl.handle.net/10203/103242 | - |
dc.description.abstract | Distributed denial of service (DDoS) attacks, which are a major threat on the Internet, have recently become more sophisticated as a result of their ability to exploit application-layer vulnerabilities. Most defense methods are designed for detecting DDoS attacks on IP and TCP layers and consequently have difficulty in detecting this new type of DDoS attack. With the profiling of web browsing behavior, the sequence order of web page requests can be used for detecting the application-layer DDoS (App-DDoS) attacks. However, the sequence order may be more harmful than helpful in the profiling of web browsing behaviors because it varies significantly for different individuals and different browsing behaviors. This article introduces a sequence-order-independent method for the profiling of network traffic and the detection of a new type of App-DDoS attacks. Four attributes are extracted from web page request sequences without consideration of the sequence order of requested pages. A model based on the multiple principal component analysis is proposed for the profiling of normal web browsing behaviors, and its reconstruction error is used as a criterion for detecting DDoS attacks. The proposed method is experimentally confirmed with various types of new App-DDoS attacks. | - |
dc.language | English | - |
dc.publisher | SPRINGER INTERNATIONAL PUBLISHING AG | - |
dc.title | Sequence-order-independent network profiling for detecting application layer DDoS attacks | - |
dc.type | Article | - |
dc.identifier.wosid | 000306483700001 | - |
dc.type.rims | ART | - |
dc.citation.volume | 2011 | - |
dc.citation.issue | 50 | - |
dc.citation.publicationname | EURASIP JOURNAL ON WIRELESS COMMUNICATIONS AND NETWORKING | - |
dc.embargo.liftdate | 9999-12-31 | - |
dc.embargo.terms | 9999-12-31 | - |
dc.contributor.localauthor | Kim, Se-Hun | - |
dc.type.journalArticle | Article | - |
Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.