Detecting Slow Application-Layer DoS Attacks With PCA
Clifford Kemp, Chad L. Calvert, Taghi M. Khoshgoftaar · 2021
Countering Denial of Service (DoS) attacks is becoming ever more challenging with the vast resources and techniques increasingly available to attackers. One of these techniques is application-layer DoS. Due to these challenges, network security has become increasingly more challenging to ensure. Hypertext Transfer Protocol (HTTP), Hypertext Transfer Protocol Secure (HTTPS), Domain Name System (DNS), Simple Mail Transfer Protocol (SMTP), File Transfer Protocol (FTP), Voice over Internet Protocol (VoIP), and other protocol applications have seen increased attacks over the past several years. It is common for application-layer attacks to concentrate on these protocols because of some weaknesses that attackers can exploit. With some leveraging, application-layer attacks can vary, such as flood and “low and slow” attacks. Low and slow approaches are particularly well-known, mainly targeting weaknesses in the HTTP protocol, which is the most broadly used application-layer protocol on the Internet. Our paper aims to develop a generalized detection approach to identify features for application-layer DoS attacks that is not specific to a single slow DoS attack. We combine four application-layer DoS attack datasets: Slow Read, POST, Slowloris, and Apache Range Header to produce a single dataset for multiple attacks. We performed a feature extraction technique Principal Component Analysis (PCA), with the single dataset to reduce dimensionality. PCA transforms our existing dataset onto a new feature space to identify four separate application-layer attacks. We explore this method to improve six machine learners used in our work. Experimental results show that the machine learners successfully identified the multiple Slow DoS attacks with high detection while minimizing false alarm rates. The experiment demonstrates that when machine learners use Netflow features and feature extraction methods, they can discriminate and detect such attacks.