Identification of malicious behaviour in content delivery network environment
Lukáš Anda, Richard Rostecky, Marek Galinski · 2022
Content delivery networks are a popular way of distributing content over the Internet. Providing content over these networks gives the provider a set of benefits, such as easy scalability, faster data loading and protection against distributed denial of service attacks (DDoS). This paper focuses on analysis of content delivery network logs from an Nginx server along with a solution that visualizes important fields and provides an insight into user behavior. Our goal is to extract and comprehend user behavior in a way that does not take up large amounts of data as storing all data for longer periods of time is not possible. By identifying and analyzing core information, we are able to distinguish botnet, users going over their device quotas and users who are most likely forging requests by analyzing their IP addresses.