02 - A Selective Defense for Low-Rate Application Layer DDoS Attacks

Fausto Vetter (RNP)

This single presentation proposal aims at presenting the latest developments of a Brazilian project, named GT-ACTIONS, as well as new results and aspects in analysis. In this project, a new defense mechanism for low-rate application layer DDoS (Distributed Denial of Service) attacks was developed and experimentally tested in a network infrastructure dedicated to the Brazilian higher education and research community. The focus of the project is to propose a countermeasure, called SeVen (Selective Verification in Application Layer) against applications layer DDoS attacks, like HTTP-GET and HTTP-POST, which are very difficult to detect and use the least amount of resources to cause the maximum damage or disruption to victims.

