Mitigating application layer distributed denial of service attacks via effective trust management.

Saved in:
Bibliographic Details
Title: Mitigating application layer distributed denial of service attacks via effective trust management.
Authors: Yu, J.1, Fang, C.2, Lu, L.2, Li, Z.3
Source: IET Communications (Institution of Engineering & Technology). 11/5/2010, Vol. 4 Issue 16, p1952-1962. 11p.
Subjects: Denial of service attacks, Web server software, Computer network protocols, Data packeting, Java programming language, Bandwidths, Licensed products
Abstract: Nowadays, web servers are suffering from application layer distributed denial of service (DDoS) attacks, to which network layer solutions is not applicable as attackers are indistinguishable based on packets or protocols. In this study, the authors propose trust management helmet (TMH) as a partial solution to this problem, which is a lightweight mitigation mechanism that uses trust to differentiate legitimate users from attackers. Its key insight is that a server should give priority to protecting the connectivity of good users during application layer DDoS attacks, instead of identifying all the attack requests. The trust to clients is evaluated based on their visiting history and used to schedule the service to their requests. The authors introduce license, for user identification (even beyond NATs) and storing the trust information at clients. The license is cryptographically secured against forgery or replay attacks. The authors realise this mitigation mechanism and implement it as a Java package and use it for evaluation. The simulation results show that TMH is effective in mitigating session flooding attack: even with 20 times number of attackers, more than 99% of the sessions from legitimate users are accepted with TMH; whereas less than 18% are accepted without it. Moreover, we found that the additional computation cost on the deployed server is neglectable and the bandwidth overhead is acceptable. [ABSTRACT FROM AUTHOR]
Copyright of IET Communications (Institution of Engineering & Technology) is the property of Institution of Engineering & Technology and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.)
Database: Engineering Source
FullText Links:
  – Type: pdflink
Text:
  Availability: 0
Header DbId: egs
DbLabel: Engineering Source
An: 55032891
AccessLevel: 6
PubType: Academic Journal
PubTypeId: academicJournal
PreciseRelevancyScore: 0
IllustrationInfo
Items – Name: Title
  Label: Title
  Group: Ti
  Data: Mitigating application layer distributed denial of service attacks via effective trust management.
– Name: Author
  Label: Authors
  Group: Au
  Data: <searchLink fieldCode="AR" term="%22Yu%2C+J%2E%22">Yu, J.</searchLink><relatesTo>1</relatesTo><br /><searchLink fieldCode="AR" term="%22Fang%2C+C%2E%22">Fang, C.</searchLink><relatesTo>2</relatesTo><br /><searchLink fieldCode="AR" term="%22Lu%2C+L%2E%22">Lu, L.</searchLink><relatesTo>2</relatesTo><br /><searchLink fieldCode="AR" term="%22Li%2C+Z%2E%22">Li, Z.</searchLink><relatesTo>3</relatesTo>
– Name: TitleSource
  Label: Source
  Group: Src
  Data: <searchLink fieldCode="JN" term="%22IET+Communications+%28Institution+of+Engineering+%26+Technology%29%22">IET Communications (Institution of Engineering & Technology)</searchLink>. 11/5/2010, Vol. 4 Issue 16, p1952-1962. 11p.
– Name: Subject
  Label: Subjects
  Group: Su
  Data: <searchLink fieldCode="DE" term="%22Denial+of+service+attacks%22">Denial of service attacks</searchLink><br /><searchLink fieldCode="DE" term="%22Web+server+software%22">Web server software</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+network+protocols%22">Computer network protocols</searchLink><br /><searchLink fieldCode="DE" term="%22Data+packeting%22">Data packeting</searchLink><br /><searchLink fieldCode="DE" term="%22Java+programming+language%22">Java programming language</searchLink><br /><searchLink fieldCode="DE" term="%22Bandwidths%22">Bandwidths</searchLink><br /><searchLink fieldCode="DE" term="%22Licensed+products%22">Licensed products</searchLink>
– Name: Abstract
  Label: Abstract
  Group: Ab
  Data: Nowadays, web servers are suffering from application layer distributed denial of service (DDoS) attacks, to which network layer solutions is not applicable as attackers are indistinguishable based on packets or protocols. In this study, the authors propose trust management helmet (TMH) as a partial solution to this problem, which is a lightweight mitigation mechanism that uses trust to differentiate legitimate users from attackers. Its key insight is that a server should give priority to protecting the connectivity of good users during application layer DDoS attacks, instead of identifying all the attack requests. The trust to clients is evaluated based on their visiting history and used to schedule the service to their requests. The authors introduce license, for user identification (even beyond NATs) and storing the trust information at clients. The license is cryptographically secured against forgery or replay attacks. The authors realise this mitigation mechanism and implement it as a Java package and use it for evaluation. The simulation results show that TMH is effective in mitigating session flooding attack: even with 20 times number of attackers, more than 99% of the sessions from legitimate users are accepted with TMH; whereas less than 18% are accepted without it. Moreover, we found that the additional computation cost on the deployed server is neglectable and the bandwidth overhead is acceptable. [ABSTRACT FROM AUTHOR]
– Name: AbstractSuppliedCopyright
  Label:
  Group: Ab
  Data: <i>Copyright of IET Communications (Institution of Engineering & Technology) is the property of Institution of Engineering & Technology and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.)
PLink https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=egs&AN=55032891
RecordInfo BibRecord:
  BibEntity:
    Identifiers:
      – Type: doi
        Value: 10.1049/iet-com.2009.0809
    Languages:
      – Code: eng
        Text: English
    PhysicalDescription:
      Pagination:
        PageCount: 11
        StartPage: 1952
    Subjects:
      – SubjectFull: Denial of service attacks
        Type: general
      – SubjectFull: Web server software
        Type: general
      – SubjectFull: Computer network protocols
        Type: general
      – SubjectFull: Data packeting
        Type: general
      – SubjectFull: Java programming language
        Type: general
      – SubjectFull: Bandwidths
        Type: general
      – SubjectFull: Licensed products
        Type: general
    Titles:
      – TitleFull: Mitigating application layer distributed denial of service attacks via effective trust management.
        Type: main
  BibRelationships:
    HasContributorRelationships:
      – PersonEntity:
          Name:
            NameFull: Yu, J.
      – PersonEntity:
          Name:
            NameFull: Fang, C.
      – PersonEntity:
          Name:
            NameFull: Lu, L.
      – PersonEntity:
          Name:
            NameFull: Li, Z.
    IsPartOfRelationships:
      – BibEntity:
          Dates:
            – D: 05
              M: 11
              Text: 11/5/2010
              Type: published
              Y: 2010
          Identifiers:
            – Type: issn-print
              Value: 17518628
          Numbering:
            – Type: volume
              Value: 4
            – Type: issue
              Value: 16
          Titles:
            – TitleFull: IET Communications (Institution of Engineering & Technology)
              Type: main
ResultId 1