Denial of Service in Web-Domains: Building Defenses Against Next-Generation Attack Behavior

dc.contributor.advisorVlajic, Natalija
dc.creatorStevanovic, Dusan
dc.date.accessioned2016-11-25T13:58:18Z
dc.date.available2016-11-25T13:58:18Z
dc.date.copyright2016-05-02
dc.date.issued2016-11-25
dc.date.updated2016-11-25T13:58:17Z
dc.degree.disciplineComputer Science
dc.degree.levelDoctoral
dc.degree.namePhD - Doctor of Philosophy
dc.description.abstractThe existing state-of-the-art in the field of application layer Distributed Denial of Service (DDoS) protection is generally designed, and thus effective, only for static web domains. To the best of our knowledge, our work is the first that studies the problem of application layer DDoS defense in web domains of dynamic content and organization, and for next-generation bot behaviour. In the first part of this thesis, we focus on the following research tasks: 1) we identify the main weaknesses of the existing application-layer anti-DDoS solutions as proposed in research literature and in the industry, 2) we obtain a comprehensive picture of the current-day as well as the next-generation application-layer attack behaviour and 3) we propose novel techniques, based on a multidisciplinary approach that combines offline machine learning algorithms and statistical analysis, for detection of suspicious web visitors in static web domains. Then, in the second part of the thesis, we propose and evaluate a novel anti-DDoS system that detects a broad range of application-layer DDoS attacks, both in static and dynamic web domains, through the use of advanced techniques of data mining. The key advantage of our system relative to other systems that resort to the use of challenge-response tests (such as CAPTCHAs) in combating malicious bots is that our system minimizes the number of these tests that are presented to valid human visitors while succeeding in preventing most malicious attackers from accessing the web site. The results of the experimental evaluation of the proposed system demonstrate effective detection of current and future variants of application layer DDoS attacks.
dc.identifier.urihttp://hdl.handle.net/10315/32673
dc.language.isoen
dc.rightsAuthor owns copyright, except where explicitly noted. Please contact the author directly with licensing requests.
dc.subjectCommunication
dc.subject.keywordsDistributed denial of service
dc.subject.keywordsNetwork security
dc.subject.keywordsMachine learning
dc.subject.keywordsData mining
dc.subject.keywordsStatistical analysis
dc.subject.keywordsWeb crawler
dc.subject.keywordsBots
dc.subject.keywordsBotnets
dc.subject.keywordsApplication layer
dc.titleDenial of Service in Web-Domains: Building Defenses Against Next-Generation Attack Behavior
dc.typeElectronic Thesis or Dissertation

Files

Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Stevanovic_Dusan_M_2016_Phd.pdf
Size:
3.73 MB
Format:
Adobe Portable Document Format
License bundle
Now showing 1 - 2 of 2
No Thumbnail Available
Name:
license.txt
Size:
1.83 KB
Format:
Plain Text
Description:
No Thumbnail Available
Name:
YorkU_ETDlicense.txt
Size:
3.38 KB
Format:
Plain Text
Description: