Low interaction honeypot as the defense mechanism against Slowloris attack on the web server

8Citations
Citations of this article
52Readers
Mendeley users who have this article in their library.

This article is free to access.

Abstract

Threats and attacks on internet services are in line with developments in internet technology. One of the main risks is Distributed Denial of Service (DDoS). In this paper, we focus on the Slowloris attack which is an open-source DDoS attacker that generally attacks the Apache webserver. Apache is one of the most popular web servers in the world and is still used by many companies. This research presents another way to reduce attacks to the firewalls and load a counterweight by using a low interaction honeypot, HoneyPy. In normal conditions, attack schemes and defense mechanisms are evaluated by conducting experiments. Slowloris attacks cause high traffic because it prevents the socket from closing, so the webserver cannot handle other connections from legitimate users. When defense mechanisms are applied to the network, Slowloris attacks that enter the webserver are minimized because most packets are discarded and directed to the honeypot without the attacker's knowledge. It seems like the attacker has managed to attack the web server even when the attack becomes slower.

Cite

CITATION STYLE

APA

Fitri, N. R., Budi, A. H. S., Kustiawan, I., & Suwono, S. E. (2020). Low interaction honeypot as the defense mechanism against Slowloris attack on the web server. In IOP Conference Series: Materials Science and Engineering (Vol. 850). Institute of Physics Publishing. https://doi.org/10.1088/1757-899X/850/1/012037

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free