Recent analysis of forged request headers constitued by HTTP DDoS

Application Layer Distributed Denial of Service (DDoS) attacks are very challenging to detect. The shortfall at the application layer allows formation of HTTP DDoS as the request headers are not compulsory to be attached in an HTTP request. Furthermore, the header is editable, thus providing an atta...

Full description

Bibliographic Details
Main Authors: Jaafar, Abdul Ghafar (Author), Ismail, Saiful Adli (Author), Abdullah, Mohd. Shahidan (Author), Kama, Nazri (Author), Azmi, Azri (Author), Mohd. Yusop, Othman (Author)
Format: Article
Language:English
Published: MDPI AG, 2020-07.
Subjects:
Online Access:Get fulltext
LEADER 01962 am a22001933u 4500
001 91381
042 |a dc 
100 1 0 |a Jaafar, Abdul Ghafar  |e author 
700 1 0 |a Ismail, Saiful Adli  |e author 
700 1 0 |a Abdullah, Mohd. Shahidan  |e author 
700 1 0 |a Kama, Nazri  |e author 
700 1 0 |a Azmi, Azri  |e author 
700 1 0 |a Mohd. Yusop, Othman  |e author 
245 0 0 |a Recent analysis of forged request headers constitued by HTTP DDoS 
260 |b MDPI AG,   |c 2020-07. 
856 |z Get fulltext  |u http://eprints.utm.my/id/eprint/91381/1/AbdulGhafarJaafar2020_RecentAnalysisofForgedRequestHeaders.pdf 
520 |a Application Layer Distributed Denial of Service (DDoS) attacks are very challenging to detect. The shortfall at the application layer allows formation of HTTP DDoS as the request headers are not compulsory to be attached in an HTTP request. Furthermore, the header is editable, thus providing an attacker with the advantage to execute HTTP DDoS as it contains almost similar request header that can emulate a genuine client request. To the best of the authors' knowledge, there are no recent studies that provide forged request headers pattern with the execution of the current HTTP DDoS attack scripts. Besides that, the current dataset for HTTP DDoS is not publicly available which leads to complexity for researchers to disclose false headers, causing them to rely on old dataset rather than more current attack patterns. Hence, this study conducted an analysis to disclose forged request headers patterns created by HTTP DDoS. The results of this study successfully disclose eight forged request headers patterns constituted by HTTP DDoS. The analysis was executed by using actual machines and eight real attack scripts which are capable of overwhelming a web server in a minimal duration. The request headers patterns were explained supported by a critical analysis to provide the outcome of this paper. 
546 |a en 
650 0 4 |a T58.5-58.64 Information technology