Enhanced detection algorithms to detect http ddos

A web application utilizes Hypertext Transfer Protocol (HTTP) to surf client requests. This protocol is used widely, especially in business areas such as in online transactions and websites, including in government websites. A client delivers information to a server carried by a client web browser....

Full description

Bibliographic Details
Main Authors: Jaafar, G. A., Abdullah, S. M., Adli, S.
Format: Article
Language:English
Published: World Academy of Research in Science and Engineering 2019
Subjects:
Online Access:http://eprints.utm.my/89515/1/GhafarAJaafar2019_EnhancedDetectionAlgorithms.pdf
_version_ 1796864845592657920
author Jaafar, G. A.
Abdullah, S. M.
Adli, S.
author_facet Jaafar, G. A.
Abdullah, S. M.
Adli, S.
author_sort Jaafar, G. A.
collection ePrints
description A web application utilizes Hypertext Transfer Protocol (HTTP) to surf client requests. This protocol is used widely, especially in business areas such as in online transactions and websites, including in government websites. A client delivers information to a server carried by a client web browser. An HTTP distributed denial of service (DDoS) attack occurs when the attacker is able to mimic client information, which makes a DDoS attack at the application layer difficult to distinguish as the traffic pattern is similar to a genuine request. Furthermore, it is not compulsory for the client to present the GET headers component to a web server during the GET request transaction. Existing detection of HTTP DDoS attacks still faces challenges in differentiating between authentic and bogus GET requests in real time. In this paper, a fast algorithm (FARGO) method to detect HTTP DDoS attacks is introduced. FARGO consists of three detection algorithms to recognize HTTP DDoS categories as request flooding attacks. The assessment of the proposed detection system was conducted in real experimental conditions with real attack scripts. The proposed detection method provided expected outcomes with improvements of 11.30% for true positive rates and 8.9% for false-positive rates.
first_indexed 2024-03-05T20:48:00Z
format Article
id utm.eprints-89515
institution Universiti Teknologi Malaysia - ePrints
language English
last_indexed 2024-03-05T20:48:00Z
publishDate 2019
publisher World Academy of Research in Science and Engineering
record_format dspace
spelling utm.eprints-895152021-02-09T04:26:23Z http://eprints.utm.my/89515/ Enhanced detection algorithms to detect http ddos Jaafar, G. A. Abdullah, S. M. Adli, S. T Technology (General) A web application utilizes Hypertext Transfer Protocol (HTTP) to surf client requests. This protocol is used widely, especially in business areas such as in online transactions and websites, including in government websites. A client delivers information to a server carried by a client web browser. An HTTP distributed denial of service (DDoS) attack occurs when the attacker is able to mimic client information, which makes a DDoS attack at the application layer difficult to distinguish as the traffic pattern is similar to a genuine request. Furthermore, it is not compulsory for the client to present the GET headers component to a web server during the GET request transaction. Existing detection of HTTP DDoS attacks still faces challenges in differentiating between authentic and bogus GET requests in real time. In this paper, a fast algorithm (FARGO) method to detect HTTP DDoS attacks is introduced. FARGO consists of three detection algorithms to recognize HTTP DDoS categories as request flooding attacks. The assessment of the proposed detection system was conducted in real experimental conditions with real attack scripts. The proposed detection method provided expected outcomes with improvements of 11.30% for true positive rates and 8.9% for false-positive rates. World Academy of Research in Science and Engineering 2019 Article PeerReviewed application/pdf en http://eprints.utm.my/89515/1/GhafarAJaafar2019_EnhancedDetectionAlgorithms.pdf Jaafar, G. A. and Abdullah, S. M. and Adli, S. (2019) Enhanced detection algorithms to detect http ddos. International Journal of Advanced Trends in Computer Science and Engineering, 8 (4). ISSN 2278-3091 http://www.dx.doi.org/10.30534/ijatcse/2019/86842019 DOI: 10.30534/ijatcse/2019/86842019
spellingShingle T Technology (General)
Jaafar, G. A.
Abdullah, S. M.
Adli, S.
Enhanced detection algorithms to detect http ddos
title Enhanced detection algorithms to detect http ddos
title_full Enhanced detection algorithms to detect http ddos
title_fullStr Enhanced detection algorithms to detect http ddos
title_full_unstemmed Enhanced detection algorithms to detect http ddos
title_short Enhanced detection algorithms to detect http ddos
title_sort enhanced detection algorithms to detect http ddos
topic T Technology (General)
url http://eprints.utm.my/89515/1/GhafarAJaafar2019_EnhancedDetectionAlgorithms.pdf
work_keys_str_mv AT jaafarga enhanceddetectionalgorithmstodetecthttpddos
AT abdullahsm enhanceddetectionalgorithmstodetecthttpddos
AT adlis enhanceddetectionalgorithmstodetecthttpddos