Analysis of realization and method of detecting low-intensity HTTP-attacks

Journal Title: Проблеми телекомунікацій - Year 2013, Vol 0, Issue 3

Abstract

The analysis of realization features of low-intensity HTTP-attacks was performed. Three types of low intensity attacks were highlighted: Slowloris, Slow POST attack and Slow READ attack. Scenarios of each type of low-intensity attacks were described. Features of this type of attacks in comparison with low-level attacks such as "denial of service" were selected: they do not require a large Number of resources from the attacking machine, and they are difficult for the detection, since their parameters are similar to legitimate traffic. All three types of attacks have been implemented using the tool "slowhttptest". The web server Apache parameter by which can be realized these vulnerabilities were obtained. Different configurations of the server Apache, which exposed to attacks of this type, have been investigated. The basic parameters of the attacks, in which server Apache transforms into a state, where it cannot service requests have been allocated. For each type of attacks the characteristic features were highlighted. Parameters of http-request, which assume the detection of this type attacks highlighted. The analysis of mathematical tools of building the models for the systems for these types of attacks detection on the basis of the obtained parameters was performed.

Authors and Affiliations

Anders Carlsson, Evgeny Duravkin, Anastasya Sergeevna Loktionova

Keywords

Related Articles

Математическая модель атак и защит в программно-конфигурируемых сетях

В статье рассматривается активный способ организации борьбы с несанкционированным вмешательством в работу программно-конфигурируемой сети связи SDN. Упреждающие мероприятия планируются на базе известных данных об уязвимо...

Analytical model for estimates the capital cost of construction of next generation urban optical access network

The paper proposed an analytical model to estimate the capital cost of deployment next generation optical access (NGOA) network for the urban area. This model is used for solution the problems: of optical access technolo...

Анализ работы метода оптимизированного кэширования данных в сети доставки контента

В данной работе представлена структурная схема организации работы CDN в виде трех взаимодополняющих плоскостей. Каждая из плоскостей описывает определенную функциональную составляющую и взаимодействует с другими плоскост...

Research of the allocation method the time-frequency resource of the LTE downlink using RAT 1

A research on the previously proposed method for allocation of time-frequency resource of the LTE downlink has been conducted. The method is based on the solution of the optimization problem on the allocation of resource...

Analysis of the method of optimized data caching in the Content Delivery Network

Concept of Content Delivery Network (CDN) system and methods of caching data on edge servers were considered in this paper. The main task of the CDN network is providing the qualitative information delivery to the end us...

Download PDF file
  • EP ID EP389462
  • DOI -
  • Views 109
  • Downloads 0

How To Cite

Anders Carlsson, Evgeny Duravkin, Anastasya Sergeevna Loktionova (2013). Analysis of realization and method of detecting low-intensity HTTP-attacks. Проблеми телекомунікацій, 0(3), 61-70. https://europub.co.uk/articles/-A-389462