A Novel Machine Learning Approach to Detect Application Layer DDoS Attacks
V. Jyothsna, Sarabu Naga Swetha, P. Lalan Kumar, Vadde Uday Kumar, Putta Kalyan, K. Srilakshmi · 2024
Attackers use application-layer DDoS (App-DDoS) attacks, which aim to bring down the victim's server by sending fake packets in its direction. Because malicious packets mimic the behavior of legitimate users and contain real source IP addresses, neither attackers nor IDS can distinguish packets from legitimate users. Regardless of the kind, the primary objective of DDoS attackers is to make the victim servers react so slowly that they become unusable or shut down entirely. They overburden the victim server's bottleneck resources in order to do this. For application-layer DDoS attacks, CPU cycles, RAM, I/O bandwidth, disk bandwidth or database bandwidth and TCP/IP stacks are the intended bottleneck resources. Through the use of valid requests, the attacker overwhelms the bottleneck resources in App-DDoS attacks. An attacker overwhelms limited resources with real requests in App-DDoS attacks. Any bot that wants to participate in an attack must first establish a TCP connection to the victim's server, which requires a real IP address to perform such an attack. An App DDoS security technique's primary goal is to identify and separate malicious traffic from legal traffic. Because attackers intentionally generate App-DDoS traffic to mimic real traffic, this problem is challenging. However, experienced hackers are always evolving their toolkits and creating increasingly complex App DDoS attacks, making it harder to identify attack activity. On the other hand, the victim server can stop all traffic coming from the attack sources once the attacked traffic is identified. Over the past decade, a number of traditional, heuristic, and more recently, machine learning (ML)-based methods have been developed to identify and differentiate App-DDoS activity from real traffic. Previously used traditional strategies, such are heuristic and classic approaches, use traffic engineer-programmed rules to identify App DDoS activity. Due to the constantly changing and evolving nature of App-DDoS attacks, conventional methods have not been very effective in detecting App-DDoS traffic. CICIDS-2017 dataset contains different types of DDoS attacks such as slowloris, httptest, goldeneye, hulk. This study proposes a feature selection strategy to improve the speed and efficiency of a machine learning solution for detecting DDoS attacks, leading to a significant reduction in feature subsets and ensemble technique to detect AL-DDoS attacks.