HTTP Low and Slow DoS Attack Detection using LSTM based deep learning
Bronjon Gogoi, Tasiruddin Ahmed · 2022 IEEE 19th India Council International Conference (INDICON) · 2022
HTTP low and slow DoS is a kind of attack wherein an attacker sends a stream of very slow HTTP requests to a web server. These slow HTTP requests are aimed at specific applications or server resources. By sending HTTP requests very slowly, these attacks waste the server’s resources as the server has to wait for the slow HTTP requests to be completed. HTTP low and slow DoS attacks are primarily used against thread-based web servers like Apache and IIS. By sending very slow requests, these attacks tie up the server threads. This results in a Denial of service for other legitimate users. Since low and slow DoS attacks do not require flooding or sending a large number of HTTP requests, they are not easily detected. Traditional network layer tools cannot detect low and slow DoS attacks and other mitigation and detection strategies are required for the detection of low and slow DoS attacks. In this paper, we propose an LSTM deep learning-based approach for detecting HTTP DoS attacks. The proposed study was conducted on the CIC DoS dataset and a synthetically generated dataset and achieved an impressive accuracy of 0.99.