Abstract
Brute-force attacks against Web site are a common area of concern, both for Web site owners and hosters. This is mainly due to the impact of potential compromises resulting therefrom, and the increased load on the underlying infrastructure. The latter may even result in a Denial-of-Service (DoS). Detecting brute-force attacks — and ultimately mitigating them — is therefore of great importance. In this paper, we take the first step in this direction, by presenting a network-based approach for detecting HTTP(S) dictionary attacks using NetFlow/IPFIX. We have developed a prototype Intrusion Detection System (IDS), released as open-source software, by means of which we can achieve accuracies close to 100%.
Original language | Undefined |
---|---|
Title of host publication | Proceedings of the 2015 IFIP/IEEE International Symposium on Integrated Network Management (IM 2015) |
Place of Publication | USA |
Publisher | IEEE Communications Society |
Pages | 862-865 |
Number of pages | 4 |
ISBN (Print) | 978-3-901882-76-0 |
DOIs | |
Publication status | Published - May 2015 |
Event | 14th IFIP/IEEE International Symposium on Integrated Network Management, IM 2015: Integrated Management in the Age of Big Data - Shaw Centre, Ottawa, Canada Duration: 11 May 2015 → 15 May 2015 Conference number: 14 http://im2015.ieee-im.org/ |
Publication series
Name | |
---|---|
Publisher | IEEE Communications Society |
Conference
Conference | 14th IFIP/IEEE International Symposium on Integrated Network Management, IM 2015 |
---|---|
Abbreviated title | IM 2015 |
Country/Territory | Canada |
City | Ottawa |
Period | 11/05/15 → 15/05/15 |
Internet address |
Keywords
- EWI-26079
- IR-96980
- METIS-312637