Please use this identifier to cite or link to this item: https://dspace.iiti.ac.in/handle/123456789/4965
Full metadata record
DC FieldValueLanguage
dc.contributor.authorHubballi, Neminathen_US
dc.date.accessioned2022-03-17T01:00:00Z-
dc.date.accessioned2022-03-17T15:36:15Z-
dc.date.available2022-03-17T01:00:00Z-
dc.date.available2022-03-17T15:36:15Z-
dc.date.issued2018-
dc.identifier.citationTripathi, N., & Hubballi, N. (2018). Slow rate denial of service attacks against HTTP/2 and detection. Computers and Security, 72, 255-272. doi:10.1016/j.cose.2017.09.009en_US
dc.identifier.issn0167-4048-
dc.identifier.otherEID(2-s2.0-85032828587)-
dc.identifier.urihttps://doi.org/10.1016/j.cose.2017.09.009-
dc.identifier.urihttps://dspace.iiti.ac.in/handle/123456789/4965-
dc.description.abstractHTTP/2 is a newly standardized protocol designed to efficiently utilize the TCP's transmission rate and has other advantages compared to HTTP/1.1. However its threat vectors are not completely understood yet. Our contribution in this paper is threefold. First we describe few new threat vectors of HTTP/2 which are Slow Rate DoS attacks and can be launched by injecting specially crafted HTTP requests. We perform an empirical evaluation of these attacks against popular web servers and report that majority of web servers are vulnerable to these attacks. We also test the effectiveness of proposed attacks using both clear text and encrypted HTTP/2 requests and find that the attack is effective independent of the request type. Second we compare structurally similar attacks with HTTP/1.1 and report that HTTP/2 has more threat vectors compared to its predecessor. Third we propose an anomaly detection scheme which uses chi-square (χ2) test between traffic profiles generated in normal and attack scenarios to detect these attacks. © 2017 Elsevier Ltden_US
dc.language.isoenen_US
dc.publisherElsevier Ltden_US
dc.sourceComputers and Securityen_US
dc.subjectComputer crimeen_US
dc.subjectDenial-of-service attacken_US
dc.subjectHypertext systemsen_US
dc.subjectStatistical testsen_US
dc.subjectWeb servicesen_US
dc.subjectAnomaly detectionen_US
dc.subjectAttack scenariosen_US
dc.subjectChi-square testsen_US
dc.subjectEmpirical evaluationsen_US
dc.subjectTraffic profileen_US
dc.subjectTransmission ratesen_US
dc.subjectVulnerability assessmentsen_US
dc.subjectWeb serversen_US
dc.subjectHTTPen_US
dc.titleSlow rate denial of service attacks against HTTP/2 and detectionen_US
dc.typeJournal Articleen_US
Appears in Collections:Department of Computer Science and Engineering

Files in This Item:
There are no files associated with this item.


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.

Altmetric Badge: