Application Layer DDoS Attack Detection In The Presence Of Flash Crowds

dc.contributor.advisorYalemzewd, Negash (PhD)
dc.contributor.authorBiruk, Asmare
dc.date.accessioned2020-07-06T05:56:59Z
dc.date.accessioned2023-11-04T15:14:42Z
dc.date.available2020-07-06T05:56:59Z
dc.date.available2023-11-04T15:14:42Z
dc.date.issued2017-09
dc.description.abstractApplication layer DDoS attacks are growing at alarming rate in terms of attack intensity and number of attack. Attackers target websites of government agencies as well as private business for different motives. One particular research problem is distinguishing Application layer DDoS attacks from flash crowds. Both flash crowds and application layer DDoS attack cause denial of service. Flash crowds come from sudden surge in traffic of legitimate requests. Whereas, application layer DDoS attacks are intentionally generated by attackers to cause denial of service. Distinguishing between Application layer DDoS attacks and flash crowd is important because the action taken to address both problems is different. Flash crowds are legitimate requests which should be serviced. Whereas, Application layer DDoS attacks are malicious requests that should not be serviced. Furthermore, the source of application layer DDoS attacks should be blocked from making further requests. In this research, supervised machine learning based application layer DDoS detection approach was proposed to distinguish between application layer DDoS attack and flash crowd. Features that help distinguish application layer DDoS attacks from legitimate flash crowds were identified. Six supervised classifiers were evaluated using World cup 98 flash crowd dataset and experimentally generated application layer DDoS attack dataset. We have selected decision tree as supervised classifier in our detection system based on evaluation result. Decision tree had F1 score of 99.45% and False positive rate of 0.47%.en_US
dc.identifier.urihttp://etd.aau.edu.et/handle/123456789/21881
dc.language.isoen_USen_US
dc.publisherAddis Ababa Universityen_US
dc.subjectAPP-DDoS attacken_US
dc.subjectapplication layeren_US
dc.subjectdecision tree classifieren_US
dc.subjectflash crowden_US
dc.subjectlayer7 attacksen_US
dc.subjectsupervised machine learningen_US
dc.titleApplication Layer DDoS Attack Detection In The Presence Of Flash Crowdsen_US
dc.typeThesisen_US

Files

Original bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
Biruk Asmare.pdf
Size:
1.9 MB
Format:
Adobe Portable Document Format
License bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
1.71 KB
Format:
Plain Text
Description: