Re: Intrusion Detection Evaluation Datasets

Seth Hall <[email protected]>
Newsgroups gmane.comp.security.ids
Message-ID <[email protected]>
On Mar 19, 2009, at 5:14 PM, Damiano Bolzoni wrote:
> Once I obfuscate some details, I can provide you the traces. We have  
> been also trying to understand why somebody would do such a stupid  
> "attack" (as also Stefano pointed out, it's only to consume  
> resources, whatever they are). As I said, few requests per second do  
> no affect the web server performance, but looking at the number of  
> hosts involved, it's clear the attacker can easily raise the bar.


This is an issue that I've considered approaching because we will  
occasionally see these sorts of attacks on web servers on our  
network.  They should be detectable more generically by building an  
average of the Content-Length header values for a address/port pair  
and watching for when that value begins to sway upwards.

Thanks for bringing up the subject, I've been looking for HTTP DoS  
attack vectors to monitor for and this has brought up several ideas  
that I can implement.

   .Seth

---
Seth Hall
Network Security - Office of the CIO
The Ohio State University
Phone: 614-292-9721
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.