Mitigating Slow Hypertext Transfer Protocol Distributed Denial of Service Attacks in Software Defined Networks

Authors

  • Oluwatobi Shadrach Akanji Department of Computer Science, Federal University of Technology Minna, Nigeria
  • Opeyemi Aderiike Abisoye Department of Computer Science, Federal University of Technology Minna, Nigeria
  • Mohammed Awwal Iliyasu Department of Computer Science, Federal University of Technology Minna, Nigeria

DOI:

https://doi.org/10.32890/jict2021.20.3.1

Keywords:

Genetic Algorithm, Slow DDoS mitigation, Slow Distributed Denial of Service, Software Defined Network, Support Vector Machine

Abstract

Distributed Denial of Service (DDoS) attacks has been one of the persistent forms of attacks on information technology infrastructure connected to public networks due to the ease of access to DDoS attack tools. Researchers have been able to develop several techniques to curb volumetric DDoS which overwhelms the target with a large number of request packets. However, compared to slow DDoS, limited number of research has been executed on mitigating slow DDoS. Attackers have resorted to slow DDoS because it mimics the behaviour of a slow legitimate client thereby causing service unavailability. This paper provides the scholarly community with an approach to boosting service availability in web servers under slow Hypertext Transfer Protocol (HTTP) DDoS attacks through attack detection using Genetic Algorithm and Support Vector Machine which facilitates attack mitigation in a Software-Defined Networking (SDN) environment simulated in GNS3. Genetic algorithm was used to select the Netflow features which indicates the presence of an attack and also determine the appropriate regularization parameter, C, and gamma parameter for the Support Vector Machine classifier. Results obtained showed that the classifier had detection accuracy, Area Under Receiver Operating Curve (AUC), true positive rate, false positive rate and a false negative rate of 99.89%, 99.89%, 99.95%, 0.18%, and 0.05% respectively. Also, the algorithm for subsequent implementation of the selective adaptive bubble burst mitigation mechanism was presented. This study contributes to the ongoing research in detecting and mitigating slow HTTP DDoS attacks with emphasis on the use of machine learning classification and meta-heuristic algorithms.

References

Agarwal, S. (2014). Data mining: Data mining concepts and techniques. Proceedings - 2013 International Conference on Machine Intel­­ ligence Research and Advancement, ICMIRA 2013, 203–207. https://doi.org/10.1109/ICMIRA.2013.45

Ameyed, D., Jaafar, F., & Fattahi, J. (2015). A slow read attack using cloud. Proceedings of the 2015 7th International Conference on Electronics, Computers and Artificial Intelligence, ECAI 2015, SSS33–SSS38. https://doi.org/10.1109/ECAI.2015.7301202

Beigi-Mohammadi, N., Barna, C., Shtern, M., Khazaei, H., & Litoiu, M. (2017). CAAMP: Completely automated DDoS attack mitigation platform in hybrid clouds. 2016 12th International Conference on Network and Service Management, CNSM 2016 Journal of ICT, 20, No. 3 (July) 2021, pp: 277– and Workshops, 3rd International Workshop on Management of SDN and NFV, ManSDN/NFV 2016, and International Workshop on Green ICT and Smart Networking, GISN 2016, 136–143. https://doi.org/10.1109/CNSM.2016.7818409

Benzekki, K., El Fergougui, A., & Elbelrhiti Elalaoui, A. (2016). Software-defined networking (SDN): A survey. Security and Communication Networks, 9(18), 5803–5833. https://doi.org/10.1002/sec.1737

Bhunia, S. S., & Gurusamy, M. (2017). Dynamic attack mitigation using SDN. 2017 27th International Telecommunication Networks and Applications Conference, ITNAC 2017, 2017-Janua, 1–6. https://doi.org/10.1109/ATNAC.2017.8215430

Brynielsson, J., & Sharma, R. (2015). Detectability of low-rate HTTP server DoS attacks using spectral analysis. Proceedings of the 2015 IEEE/ACM International Conference on Advances in Social Networks Analysis and Mining, ASONAM 2015, 954–961. https://doi.org/10.1145/2808797.2808810

Calvert, C. L., & Khoshgoftaar, T. M. (2019). Impact of class distribution on the detection of slow HTTP DoS attacks using Big Data. Journal of Big Data. https://doi.org/10.1186/s40537-019-0230-3

Cambiaso, E., Papaleo, G., & Aiello, M. (2017). Slowcomm: Design, development and performance evaluation of a new slow DoS attack. Journal of Information Security and Applications, 35, 23–31. https://doi.org/10.1016/j.jisa.2017.05.005

Cambiaso, E., Papaleo, G., Chiola, G., & Aiello, M. (2013). Slow DoS attacks: Definition and categorisation. International Journal of Trust Management in Computing and Communications, 1(3/4), 300. https://doi.org/10.1504/ijtmcc.2013.056440

Cusack, B., & Tian, Z. (2016). Detecting and tracing slow attacks on mobile phone user service. Proceedings of the 14th Australian Digital Forensics Conference, ADF 2016, (December), 4–10. https://doi.org/10.4225/75/58a54b013185a

Dabbagh, M., Hamdaoui, B., Guizani, M., & Rayes, A. (2015). Software-defined networking security: pros and cons. IEEE Communications Magazine, 53(6), 73-79. https://doi.org/10.1109/MCOM.2015.7120048.

Dantas, Y. G., Fonseca, I. E., & Nigam, V. (2017). Slow TCAM exhaustion DDoS attack. In IFIP International Conference on ICT Systems Security and Privacy Protection (pp. 17–31). https://doi.org/10.1007/978-3-319-58469-0 Journal of ICT, 20, No. 3 (July) 2021, pp: 277–

Dhanapal, A., & Nithyanandam, P. (2019). The slow HTTP distributed denial of service attack detection in cloud. Scalable Computing, 20(2), 285–298. https://doi.org/10.12694/scpe.v20i2.1501

Ezekiel, S., Divakaran, D. M., & Gurusamy, M. (2017). Dynamic attack mitigation using SDN. 2017 27th International Telecommunication Networks and Applications Conference, ITNAC 2017, 2017-Janua, 1–6. https://doi.org/10.1109/ ATNAC.2017.8215430

Foñseca, I. E., & Nigam, V. (2016). Mitigating high-rate application layer DDoS attacks in software defined networks.

Hamad, D. J., Yalda, K. G., & Okumuş, I. T. (2016). Getting traffic statistics from network devices in an SDN environment using OpenFlow. Information Technology and Systems 2015, (April), 951–956.

Hong, K., Kim, Y., Choi, H., & Park, J. (2018). SDN-assisted slow HTTP DDoS attack defense method. IEEE Communications Letters, 22(4), 688–691. https://doi.org/10.1109/LCOMM.2017.2766636

Idhammad, M., Afdel, K., & Belouch, M. (2018). Detection System of HTTP DDoS attacks in a cloud environment based on information theoretic entropy and random forest. Security and Communication Networks, 2018. https://doi.org/10.1155/2018/1263123

Jaafar, G. A., Abdullah, S. M., & Ismail, S. (2019). Review of recent detection methods for HTTP DDoS attack. Journal of Computer Networks and Communications, Vol. 2019. https://doi.org/10.1155/2019/1283472

Jazi, H. H., Gonzalez, H., Stakhanova, N., & Ghorbani, A. A. (2017). Detecting HTTP-based application layer DoS attacks on web servers in the presence of sampling. Computer Networks, 121, 25–36. https://doi.org/10.1016/j.comnet.2017.03.018

Kemp, C., Calvert, C., & Khoshgoftaar, T. M. (2018). Utilizing netflow data to detect slow read attacks. Proceedings - 2018 IEEE 19th International Conference on Information Reuse and Integration for Data Science, IRI 2018, 108–116. https://doi.org/10.1109/ IRI.2018.00023

Latah, M., & Toker, L. (2018). Artificial intelligence enabled software-defined networking: a comprehensive overview. IET networks, 8(2), 79-99. https://doi.org/10.1049/iet-net.2018.5082

Liu, H., & Kim, M. S. (2010). Real-time detection of stealthy DDoS attacks using time-series decomposition. IEEE International Conference on Communications. https://doi.org/10.1109/ICC.2010.5501975 Journal of ICT, 20, No. 3 (July) 2021, pp: 277–

Liu, S., Wang, L., Qin, J., Guo, Y., & Zuo, H. (2018). An intrusion detection model based on IPSO-SVM algorithm in wireless sensor network. Journal of Internet Technology, 19(7), 2125–2134. https://doi.org/10.3966/160792642018121907015

Lukaseder, T., Maile, L., Erb, B., & Kargl, F. (2018). SDN-assisted network-based mitigation of slow DDoS attacks. Lecture Notes of the Institute for Computer Sciences, Social-Informatics and Telecommunications Engineering, LNICST, 255, 102–121. https://doi.org/10.1007/978-3-030-01704-0_6

Ma, Y., & Guo, G. (2014). Support vector machines applications. In Support Vector Machines Applications (Vol. 9783319023). https://doi.org/10.1007/978-3-319-02300-7

Muraleedharan, N., & Janet, B. (2018). Behaviour analysis of HTTP based slow denial of service attack. Proceedings of the 2017 International Conference on Wireless Communications, Signal Processing and Networking, WiSPNET 2017, 2018-Janua, 1851–1856. https://doi.org/10.1109/WiSPNET.2017.8300082

Najafabadi, M. M., Khoshgoftaar, T. M., Napolitano, A., & Wheelus, C. (2016). RUDY attack: Detection at the network level and its important features. Proceedings of the 29th International Florida Artificial Intelligence Research Society Conference, FLAIRS 2016, 282–287.

Park, J. (2015). Analysis of slow read DoS attack and countermeasures on web servers. International Journal of Cyber-Security and Digital Forensics, 4(2), 339–353. https://doi.org/10.17781/ p001550

Perez-Diaz, J. A., Valdovinos, I. A., Choo, K. K. R., & Zhu, D. (2020). A flexible SDN-based architecture for identifying and mitigating low-rate DDoS attacks using machine learning. IEEE Access, 8, 155859–155872. https://doi.org/10.1109/ ACCESS.2020.3019330

Polat, H., & Polat, O. (2021). An intelligent software defined networking controller component to detect and mitigate denial of service attacks. Journal of Information and Communication Technology, 20(1), 57–81. https://doi.org/10.32890/jict.20.1.2021.6288

Sahoo, K. S., Tripathy, B. K., Naik, K., Ramasubbareddy, S., Balusamy, B., Khari, M., & Burgos, D. (2020). An evolutionary SVM model for DDOS attack detection in software defined networks. IEEE Access, 8, 132502–132513. https://doi.org/10.1109/ ACCESS.2020.3009733 Journal of ICT, 20, No. 3 (July) 2021, pp: 277–

Sattar, D., Matrawy, A., & Adeojo, O. (2016). Adaptive bubble burst (ABB): Mitigating DDoS attacks in software-defined networks. 2016 17th International Telecommunications Network Strategy and Planning Symposium, Networks 2016 - Conference Proceedings, 50–55. https://doi.org/10.1109/ NETWKS.2016.7751152

Schehlmann, L., & Baier, H. (2013). COFFEE : A concept based on OpenFlow to filter and erase events of botnet activity at high-speed nodes. GI-Jahrestagung, 2225–2239.

Shafieian, S., Zulkernine, M., & Haque, A. (2015). CloudZombie: Launching and detecting slow-read distributed denial of service attacks from the Cloud. Proceedings - 15th IEEE International Conference on Computer and Information Technology, CIT 2015, 14th IEEE International Conference on Ubiquitous Computing and Communications, IUCC 2015, 13th IEEE International Conference on Dependable, Autonomic and Se, 1733–1740. https://doi.org/10.1109/CIT/IUCC/DASC/PICOM.2015.261

Shtern, M., Sandel, R., Litoiu, M., Bachalo, C., & Theodorou, V. (2014). Towards mitigation of low and slow application DDoS attacks. Proceedings - 2014 IEEE International Conference on Cloud Engineering, IC2E 2014, (Vm), 604–609. https://doi.org/10.1109/IC2E.2014.38

Bhati, B. S., & Rai, C. S. (2020). Analysis of support vector machine-based intrusion detection techniques. Arabian Journal for Science and Engineering, 45(4), 2371-2383. https://doi.org/10.1007/ s13369-019-03970-z

Singh, K. J., & De, T. (2015). An approach of ddos attack detection using classifiers. In Emerging Research in Computing, Information, Communication and Applications (pp. 429-437). Springer, New Delhi. https://doi.org/10.1007/978-81-322-2550-8

Siracusano, M., Shiaeles, S., & Ghita, B. (2018, October). Detection of lddos attacks based on tcp connection parameters. In 2018 Global Information Infrastructure and Networking Symposium (GIIS) (pp. 1-6). IEEE. https://doi.org/10.1109/ GIIS.2018.8635701

Suroto, S. (2017). A review of defense against slow HTTP attack. JOIV : International Journal on Informatics Visualization, 1(4), 127. https://doi.org/10.30630/joiv.1.4.51

Swami, R., Dave, M., & Ranga, V. (2019a). Defending DDoS against software defined networks using entropy. Proceedings - 2019 4th Journal of ICT, 20, No. 3 (July) 2021, pp: 277– International Conference on Internet of Things: Smart Innovation and Usages, IoT-SIU 2019, 1–5. https://doi.org/10.1109/IoT-SIU.2019.8777688

Swami, R., Dave, M., & Ranga, V. (2019b). Software-defined networking-based DDoS defense mechanisms. ACM Computing Survey, 52(2), 36. https://doi.org/10.1016/B978-0-12-375000-6.00124-5

Tayama, S., & Tanaka, H. (2017, June). Analysis of slow read DoS attack and communication environment. In International Conference on Mobile and Wireless Technology (pp. 350-359). Springer, Singapore. https://doi.org/10.1007/978-981-10-5281-1

Tripathi, N., & Hubballi, N. (2018). Slow rate denial of service attacks against HTTP/2 and detection. Computers and Security, 72, 255–272. https://doi.org/10.1016/j.cose.2017.09.009

Tripathi, N., Hubballi, N., & Singh, Y. (2016). How secure are web servers? An empirical study of slow HTTP DoS attacks and detection. Proceedings - 2016 11th International Conference on Availability, Reliability and Security, ARES 2016, 454–463. https://doi.org/10.1109/ARES.2016.20

Ye, Z., Sun, Y., Sun, S., Zhan, S., Yu, H., & Yao, Q. (2019). Research on network intrusion detection based on support vector machine optimized with grasshopper optimization algorithm. 2019 10th IEEE International Conference on Intelligent Data Acquisition and Advanced Computing Systems: Technology and Applications (IDAACS), 1(41301371), 378–383. https://doi.org/10.1109/ IDAACS.2019.8924234

Yeasir, M., Morshed, M., & Fakrul, M. (2015). A practical approach and mitigation techniques on application layer DDoS attack in web server. International Journal of Computer Applications, 131(1), 13–20. https://doi.org/10.5120/ijca2015907209

Yuan, B., Zou, D., Jin, H., Yu, S., & Yang, L. T. (2020). HostWatcher: Protecting hosts in cloud data centers through software-defined networking. Future Generation Computer Systems, 105, 964-972. https://doi.org/10.1016/j.future.2017.04.023

Zolotukhin, M., Hamalainen, T., Kokkonen, T., & Siltanen, J. (2016). Increasing web service availability by detecting application-layer DDoS attacks in encrypted traffic. 2016 23rd International Conference on Telecommunications, ICT 2016. https://doi.org/10.1109/ICT.2016.7500408

Downloads

Published

11-06-2021

How to Cite

Akanji, O. S., Abisoye, O. A., & Iliyasu, M. A. (2021). Mitigating Slow Hypertext Transfer Protocol Distributed Denial of Service Attacks in Software Defined Networks. Journal of Information and Communication Technology, 20(3), 277-304. https://doi.org/10.32890/jict2021.20.3.1

Research impact

Harvested 2026-09-22
10 citations, from Scopus — the highest of the sources checked

Counts differ between services because each indexes a different body of literature. None of them is the whole picture.

Identifiers DOI 10.32890/jict2021.20.3.1 OpenAlex W3175081795 Scopus 85109444610

Most read articles by the same author(s)