Nowadays the attack against the computer system is becoming very common andvulnerable. Indirect web proxy distributed denial of service attack is an increasinglycommon internet phenomenon and is capable of making the internet services unavailable.Such type of attacks cannot be easily discovered by most existing defense systems sincemalicious traffic is hidden in the aggregated traffic. Also the source of the attack trafficand normal traffic cannot be distinguished because both of them share the same IP of theproxy server. To overcome this problem, a new improved hidden semi-Markov model isproposed. Therefore, applying this proposed method protects the origin server from theweb proxy-based HTTP attacks. Web proxy’s access behavior can be regarded as thecombination of the externally observable behavior and the internal driving mechanism.The internal driving mechanism can be estimated by the observable features of proxy-toservertraffic through the hidden semi-Markov model. Hidden semi-Markov modeldescribes the dynamic behavior process of the aggregated traffic. The false positive rateis also detected with respect to the incoming traffic.Keywords: Traffic analysis, traffic modeling, distributed denial of service attack,attack detection, attack response