System for DDoS attack mitigation by discovering the attack vectors through statistical traffic analysis

被引:3
|
作者
Mirchev M.J. [1 ]
Mirtchev S.T. [1 ]
机构
[1] Faculty of Telecommunications, Technical University of Sofia, 8 Kl.Ohridski Blvd, Sofia
关键词
DDoS attack; Distributed denial-of-service; IP network security; Statistical analysis; Vector of attack;
D O I
10.1504/IJICS.2020.109479
中图分类号
学科分类号
摘要
DDoS attacks are becoming an increasing threat to the internet due to the easy availability of user-friendly attack tools. In meantime defending from such attacks is very difficult, because it is very hard to differentiate between the legitimate traffic and attack traffic and also maintain the attacked service still accessible while under attack. This paper describes a method for discovering the vector of a DDoS attack using statistical traffic analysis. The discussed methods are based on having a notification of the attack and making a statistical analysis of the attack traffic to find the vector and profiling a statistical baseline of normal traffic and discovering the abnormal traffic as a difference in the statistical parameters of TCP/IP packets in a given moment to the baseline and thus making a decision of the attack and its vector simultaneously. Copyright © 2020 Inderscience Enterprises Ltd.
引用
收藏
页码:309 / 321
页数:12
相关论文
共 50 条
  • [1] A TRAFFIC COHERENCE ANALYSIS MODEL FOR DDOS ATTACK DETECTION
    Rahmani, Hamza
    Sahli, Nabil
    Kammoun, Farouk
    SECRYPT 2009: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON SECURITY AND CRYPTOGRAPHY, 2009, : 148 - 154
  • [2] DDoS SourceTracer: An Intelligent Application for DDoS Attack Mitigation in SDN
    Aslam, Naziya
    Srivastava, Shashank
    Gore, M. M.
    COMPUTERS & ELECTRICAL ENGINEERING, 2024, 117
  • [3] DDoS Attack Detection and Mitigation at SDN Data Plane Layer
    Abdulkarem, Huda Saleh
    Dawod, Ammar
    2020 IEEE 2ND GLOBAL POWER, ENERGY AND COMMUNICATION CONFERENCE (IEEE GPECOM2020), 2020, : 322 - 326
  • [4] An on-line DDoS attack Traceback and Mitigation System based on network performance monitoring
    Su, Wei-Tsung
    Lin, Tzu-Chieh
    Wu, Chun-Yi
    Hsu, Jang-Pong
    Kuo, Yau-Hwang
    10TH INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION TECHNOLOGY, VOLS I-III: INNOVATIONS TOWARD FUTURE NETWORKS AND SERVICES, 2008, : 1467 - +
  • [5] Detection of Hijacking DDoS Attack Based on Air Interface Traffic
    Fu, Qing-Yi
    Wang, Hui-Ming
    IEEE WIRELESS COMMUNICATIONS LETTERS, 2021, 10 (10) : 2225 - 2229
  • [6] DDoS attack traffic classification in SDN using deep learning
    Ahuja N.
    Mukhopadhyay D.
    Singal G.
    Personal and Ubiquitous Computing, 2024, 28 (02) : 417 - 429
  • [7] Cloud-based DDoS attack detection and defence system using statistical approach
    Devi B.S.K.
    Subbulakshmi T.
    International Journal of Information and Computer Security, 2019, 11 (4-5) : 447 - 475
  • [8] Security Integration in DDoS Attack Mitigation Using Access Control Lists
    Yadav, Sumit Kumar
    Sharma, Kavita
    Arora, Arushi
    INTERNATIONAL JOURNAL OF INFORMATION SYSTEM MODELING AND DESIGN, 2018, 9 (01) : 56 - 76
  • [9] DDoS attack mitigation and Resource provisioning in Cloud using Fog Computing
    Deepali
    Bhushan, Kriti
    PROCEEDINGS OF THE 2017 INTERNATIONAL CONFERENCE ON SMART TECHNOLOGIES FOR SMART NATION (SMARTTECHCON), 2017, : 308 - 313
  • [10] An alert analysis approach to DDoS attack detection
    Hoque, Nazrul
    Bhattacharyya, Dhruba K.
    Kalita, Jugal K.
    2016 INTERNATIONAL CONFERENCE ON ACCESSIBILITY TO DIGITAL WORLD (ICADW), 2016, : 33 - 38