LOW-SPEED HTTP DDOS ATTACK PREVENTION MODEL FOR END USERS

Petro Ponochovny · Cybersecurity Education Science Technique · 2024

Slow HTTP DDoS attacks pose a serious threat to information systems and web services because they use sophisticated techniques to exhaust server resources. These attacks specifically target compute resource exhaustion, request throughput, or connection management at the application layer [1]. Biased modeling of such attacks requires a special approach to analyze traffic behavior and request characteristics, allowing anomalies to be detected even with minimal network activity [2], [15]. The main problem with such attacks is that they are difficult to recognize because of their similarity to legitimate traffic. Therefore, it is necessary to develop intelligent systems that can analyze the complex interaction patterns between clients and servers. The proposed model is based on a complex analysis of network activity using a layered threat detection system. The model utilizes machine learning algorithms that adapt to changing attack characteristics and improve the accuracy of detecting subtle anomalies in traffic [3], [13]. This minimizes the number of false positives and allows the system to respond quickly to changes in the attack vector. Simulation results demonstrate the effectiveness of the proposed approach, as it can respond to attacks even before the system has exhausted its resources. A feature of this model is its ability to detect early threats with low traffic intensity that do not impose a significant load on network equipment [4]. However, such threats always consume computing power and thus have a devastating impact on services. A unique advantage of this approach is that it can be integrated with existing SIEM systems, allowing for more comprehensive real-time monitoring of network activity. It also opens prospects for the realization of distributed cyber defense systems operating in multi-area networks with high traffic intensity. The proposed model provides high data processing performance through optimization of the classification algorithm and its parallel implementation. The proposed model can be integrated into various cybersecurity systems without significant impact on network performance [5], [6], [14]. The model is promising in the direction of automatic detection of new types of attacks, integration with existing SIEM systems, and faster processing of large amounts of traffic. Furthermore, the versatility of the packet group analysis mechanism allows its extension to other types of DDoS attacks based on the use of low-intensity traffic. This makes it suitable for protecting not only web applications but also other network services such as IoT platforms and cloud infrastructures. The proposed approach provides a basis for the development of intelligent defense systems against DDoS attacks. Its efficiency and adaptability will expand the capabilities of cyber defense systems, increase the resilience of information systems against modern threats, and minimize the negative impact on critical services.

Read the paper · More papers on PaperTik