{"title":"Impact Analysis of HTTP and SYN Flood DDoS Attacks on Apache 2 and IIS 10.0 Web Servers","authors":"R. Zebari, Subhi R. M. Zeebaree, Karwan Jacksi","doi":"10.1109/ICOASE.2018.8548783","DOIUrl":null,"url":null,"abstract":"Nowadays, continuously accessing Internet services is vital for the most of people. However, due to Denial of Service (DoS) and its severe type ‘Distributed Denial of Service (DDoS), online services becomes unavailable to users in sometimes. Rather than DDoS is dangerous and has serious impact on the Internet consumers, there are multiple types of that attack such Slowrise, ping of death and UDP, ICMP, SYN flood, etc. In this paper, the effect of HTTP and SYN flood attack on the most recent and widely used web servers is studied and evaluated. Systematic performance analysis is performed on Internet Information Service 10.0 (IIS 10.0) on Windows server 2016 and Apache 2 on Linux Ubuntu 16.04 Long Term Support (LTS) server. Furthermore, the key metrics of the performance are average response time, average CPU usage and standard deviation as a responsiveness, efficiency and stability of the web servers. The results show that the IIS10.0 outperformed Apache2 web server in efficiency and responsiveness during HTTP flood attack. However, Apache2 web server achievement was more responsive and performed more stability with SYN flood attack.","PeriodicalId":144020,"journal":{"name":"2018 International Conference on Advanced Science and Engineering (ICOASE)","volume":"114 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2018-10-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"36","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2018 International Conference on Advanced Science and Engineering (ICOASE)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICOASE.2018.8548783","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 36
Abstract
Nowadays, continuously accessing Internet services is vital for the most of people. However, due to Denial of Service (DoS) and its severe type ‘Distributed Denial of Service (DDoS), online services becomes unavailable to users in sometimes. Rather than DDoS is dangerous and has serious impact on the Internet consumers, there are multiple types of that attack such Slowrise, ping of death and UDP, ICMP, SYN flood, etc. In this paper, the effect of HTTP and SYN flood attack on the most recent and widely used web servers is studied and evaluated. Systematic performance analysis is performed on Internet Information Service 10.0 (IIS 10.0) on Windows server 2016 and Apache 2 on Linux Ubuntu 16.04 Long Term Support (LTS) server. Furthermore, the key metrics of the performance are average response time, average CPU usage and standard deviation as a responsiveness, efficiency and stability of the web servers. The results show that the IIS10.0 outperformed Apache2 web server in efficiency and responsiveness during HTTP flood attack. However, Apache2 web server achievement was more responsive and performed more stability with SYN flood attack.
HTTP / SYN Flood DDoS攻击对Apache 2和IIS 10.0 Web服务器的影响分析
如今,持续访问互联网服务对大多数人来说是至关重要的。但是,由于DoS (Denial of Service)攻击及其严重的分布式拒绝服务(Distributed Denial of Service)攻击,有时会导致用户无法使用在线服务。DDoS攻击有多种类型,如Slowrise、ping of death和UDP、ICMP、SYN flood等,而不是对互联网消费者有严重的影响。本文研究和评估了HTTP和SYN flood攻击对最新和最广泛使用的web服务器的影响。系统的性能分析是在Windows服务器2016上的Internet Information Service 10.0 (IIS 10.0)和Linux服务器Ubuntu 16.04上的Apache 2上进行的。此外,性能的关键指标是平均响应时间,平均CPU使用率和标准偏差作为响应,效率和web服务器的稳定性。结果表明,在HTTP flood攻击下,IIS10.0在效率和响应速度上都优于Apache2 web服务器。然而,Apache2 web服务器在SYN flood攻击下响应更快,性能更稳定。