Defense techniques for low-rate DoS attacks against application servers
-
Gabriel Maciá-Fernández; Rafael A. Rodríguez-Gómez; Jesús Esteban Díaz Verdejo
- Abstract:
- Low-rate denial of service (DoS) attacks have recently emerged as new strategies for deny-
ing networking services. Such attacks are capable of discovering vulnerabilities in protocols
or applications behavior to carry out a DoS with low-rate traffic. In this paper, we focus on a
specific attack: the low-rate DoS attack against application servers, and address the task of
finding an effective defense against this attack.
Different approaches are explored and four alternatives to defeat these attacks are sug-
gested. The techniques proposed are based on modifying the way in which an application
server accepts incoming requests. They focus on protective measures aimed at (i) prevent-
ing an attacker from capturing all the positions in the incoming queues of applications, and
(ii) randomizing the server operation to eliminate possible vulnerabilities due to predict-
able behaviors.
We extensively describe the suggested techniques, discussing the benefits and draw-
backs for each under two criteria: the attack efficiency reduction obtained, and the impact
on the normal operation of the server. We evaluate the proposed solutions in a both a sim-
ulated and a real environment, and provide guidelines for their implementation in a pro-
duction system.
- Research areas:
- Year:
- 2010
- Type of Publication:
- Article
- Keywords:
- Defense, Denial of service, Low-rate, Network security
- Journal:
- Computer Networks
- Volume:
- 54
- Pages:
- 2711-2727
- Month:
- Octubre
- ISSN:
- 1389-1286
- DOI:
- http://dx.doi.org/10.1016/j.comnet.2010.05.002
Hits: 3591