Detecting application layer DDoS attack using an advanced signature detection algorithm
Abstract
Abstract Application-layer Distributed Denial of Service (App-DDoS) attacks are an ongoing issue in the cyber security world. The attack constructs request headers and uses a large number of channels to disrupt targeted services, such as an automated attack tool. A variety of approaches have been attempted, but the detection of attacks through the identification of forged request headers is a significant gap in the research. Signature detection, which shows a strong ability to accurately identify attacks with low false positive and false negative rates, can be used to address this challenge. The paper introduces a new detection method to categorize traffic as malicious or legitimate by analyzing the request headers of the traffic. To address the concerns of various researchers regarding outdated attack patterns and the lack of datasets available for public research, the dataset used in this research is recent and representative of real-world App DDoS attack patterns. The signature detection demonstrates promising performance in detecting the attack with the latest data set, which has strong implications for adaptation to real-world applications. The key contributions of this study are the proposed detection algorithms that can detect forged request headers at the initial stage, prior to their processing by the web server, and the practical analysis, which showed that the attack strategy approach relies on the manipulation of request headers. The hybrid feature selection method employed in this research was proven to be workable and successfully identified the features which contribute significantly to the detection performance with an accuracy of 96.93%, a precision of 99.11%, a recall of 97.55%, and an F1-score of 98.32%. These results demonstrate that the signature-based detection is effective and appropriate for detecting the attack. Although Machine Learning (ML) is gaining traction, signature-based detection can still be effective for checking signatories generated by the attack in the request headers.
Article Details
Authors (5)
Abdul Ghafar Jaafar
Md Asri Ngadi
Nazri Kama
Nazhatul Hafizah Kamarudin
Khairol Shapawi