Verification of State Based Slow HTTP DDoS Prevention Method

Dau Anh Dung, Yasuhiro Nakamura · 2023

S1ow HTTP DDoS attacks involve sending numerous requests to a web server at a low rate, prolonging connection durations to saturate the server’s connection pool and disrupt legitimate client access. Detection based on traffic volume monitoring is challenging because of the low traffic volume generated per unit time. Furthermore, attackers employ tactics, such as controlling request transmission rates, timing, and connection durations, to make detection more difficult. Existing mitigation methods statistically process the packet characteristics of an attack, taking at least approximately 20 s for identification and mitigation. Additionally, the false-positive rate for legitimate connections has not been considered, necessitating validation in real-world environments. We proposed a fast detection method that observes the state transitions for each flow of HTTP communication on the network path, cutting off incomplete connections that exceed predefined thresholds for connection duration and idle time. Using data captured from actual attacks, we conducted detection experiments, achieving an average detection and mitigation time of 10 s from the start of the attack. The identification accuracy, as measured by the F1 Score, was 0.986, and the false-positive rate was 0.0096. However, there are concerns about accidentally disconnecting legitimate traffic when applying this method to web servers handling a large number of HTTP communications. Therefore, in this study, we used a web server simulating real-world operations to verify the effectiveness of the proposed method and measured a false positive rate of 0.0013, confirming the efficacy of the proposed approach.

Read the paper · More papers on PaperTik