Multiple detector methods and systems for defeating low and slow application DDoS attacks

    公开(公告)号:US10284580B2

    公开(公告)日:2019-05-07

    申请号:US15586967

    申请日:2017-05-04

    申请人: Ehab Al-Shaer Qi Duan

    发明人: Ehab Al-Shaer Qi Duan

    IPC分类号: H04L29/06 H04L29/08

    摘要: Methods and systems for detecting and defeating a low and slow application DDoS attack, comprising: computing the Entropy of a plurality of detectors, at least in part selected from a group Geo detector, a group response size detector, a group preference detector, and an individual client behavior detector, wherein the plurality of detectors each describe a feature of traffic affected by the DDoS attack; composing the plurality of detectors on one or more of a Receiver Operating Characteristic (ROC) curve basis and a correlation basis; and implementing a countermeasure to mitigate the DDoS attack.