Cargando…

A Novel Protective Framework for Defeating HTTP-Based Denial of Service and Distributed Denial of Service Attacks

The growth of web technology has brought convenience to our life, since it has become the most important communication channel. However, now this merit is threatened by complicated network-based attacks, such as denial of service (DoS) and distributed denial of service (DDoS) attacks. Despite many r...

Descripción completa

Detalles Bibliográficos
Autores principales: Saleh, Mohammed A., Abdul Manaf, Azizah
Formato: Online Artículo Texto
Lenguaje:English
Publicado: Hindawi Publishing Corporation 2015
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC4433694/
https://www.ncbi.nlm.nih.gov/pubmed/26065015
http://dx.doi.org/10.1155/2015/238230
_version_ 1782371658015703040
author Saleh, Mohammed A.
Abdul Manaf, Azizah
author_facet Saleh, Mohammed A.
Abdul Manaf, Azizah
author_sort Saleh, Mohammed A.
collection PubMed
description The growth of web technology has brought convenience to our life, since it has become the most important communication channel. However, now this merit is threatened by complicated network-based attacks, such as denial of service (DoS) and distributed denial of service (DDoS) attacks. Despite many researchers' efforts, no optimal solution that addresses all sorts of HTTP DoS/DDoS attacks is on offer. Therefore, this research aims to fix this gap by designing an alternative solution called a flexible, collaborative, multilayer, DDoS prevention framework (FCMDPF). The innovative design of the FCMDPF framework handles all aspects of HTTP-based DoS/DDoS attacks through the following three subsequent framework's schemes (layers). Firstly, an outer blocking (OB) scheme blocks attacking IP source if it is listed on the black list table. Secondly, the service traceback oriented architecture (STBOA) scheme is to validate whether the incoming request is launched by a human or by an automated tool. Then, it traces back the true attacking IP source. Thirdly, the flexible advanced entropy based (FAEB) scheme is to eliminate high rate DDoS (HR-DDoS) and flash crowd (FC) attacks. Compared to the previous researches, our framework's design provides an efficient protection for web applications against all sorts of DoS/DDoS attacks.
format Online
Article
Text
id pubmed-4433694
institution National Center for Biotechnology Information
language English
publishDate 2015
publisher Hindawi Publishing Corporation
record_format MEDLINE/PubMed
spelling pubmed-44336942015-06-10 A Novel Protective Framework for Defeating HTTP-Based Denial of Service and Distributed Denial of Service Attacks Saleh, Mohammed A. Abdul Manaf, Azizah ScientificWorldJournal Research Article The growth of web technology has brought convenience to our life, since it has become the most important communication channel. However, now this merit is threatened by complicated network-based attacks, such as denial of service (DoS) and distributed denial of service (DDoS) attacks. Despite many researchers' efforts, no optimal solution that addresses all sorts of HTTP DoS/DDoS attacks is on offer. Therefore, this research aims to fix this gap by designing an alternative solution called a flexible, collaborative, multilayer, DDoS prevention framework (FCMDPF). The innovative design of the FCMDPF framework handles all aspects of HTTP-based DoS/DDoS attacks through the following three subsequent framework's schemes (layers). Firstly, an outer blocking (OB) scheme blocks attacking IP source if it is listed on the black list table. Secondly, the service traceback oriented architecture (STBOA) scheme is to validate whether the incoming request is launched by a human or by an automated tool. Then, it traces back the true attacking IP source. Thirdly, the flexible advanced entropy based (FAEB) scheme is to eliminate high rate DDoS (HR-DDoS) and flash crowd (FC) attacks. Compared to the previous researches, our framework's design provides an efficient protection for web applications against all sorts of DoS/DDoS attacks. Hindawi Publishing Corporation 2015 2015-05-03 /pmc/articles/PMC4433694/ /pubmed/26065015 http://dx.doi.org/10.1155/2015/238230 Text en Copyright © 2015 M. A. Saleh and A. Abdul Manaf. https://creativecommons.org/licenses/by/3.0/ This is an open access article distributed under the Creative Commons Attribution License, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.
spellingShingle Research Article
Saleh, Mohammed A.
Abdul Manaf, Azizah
A Novel Protective Framework for Defeating HTTP-Based Denial of Service and Distributed Denial of Service Attacks
title A Novel Protective Framework for Defeating HTTP-Based Denial of Service and Distributed Denial of Service Attacks
title_full A Novel Protective Framework for Defeating HTTP-Based Denial of Service and Distributed Denial of Service Attacks
title_fullStr A Novel Protective Framework for Defeating HTTP-Based Denial of Service and Distributed Denial of Service Attacks
title_full_unstemmed A Novel Protective Framework for Defeating HTTP-Based Denial of Service and Distributed Denial of Service Attacks
title_short A Novel Protective Framework for Defeating HTTP-Based Denial of Service and Distributed Denial of Service Attacks
title_sort novel protective framework for defeating http-based denial of service and distributed denial of service attacks
topic Research Article
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC4433694/
https://www.ncbi.nlm.nih.gov/pubmed/26065015
http://dx.doi.org/10.1155/2015/238230
work_keys_str_mv AT salehmohammeda anovelprotectiveframeworkfordefeatinghttpbaseddenialofserviceanddistributeddenialofserviceattacks
AT abdulmanafazizah anovelprotectiveframeworkfordefeatinghttpbaseddenialofserviceanddistributeddenialofserviceattacks
AT salehmohammeda novelprotectiveframeworkfordefeatinghttpbaseddenialofserviceanddistributeddenialofserviceattacks
AT abdulmanafazizah novelprotectiveframeworkfordefeatinghttpbaseddenialofserviceanddistributeddenialofserviceattacks