Entropy and Divergence-based DDoS Attack Detection System in IoT Networks

被引:7
作者
Saiyed, Makhduma [1 ]
Al Anbagi, Irfan [1 ]
机构
[1] Univ Regina, Fac Engn & Appl Sci, Regina, SK S4S 0A2, Canada
来源
2023 19TH INTERNATIONAL CONFERENCE ON WIRELESS AND MOBILE COMPUTING, NETWORKING AND COMMUNICATIONS, WIMOB | 2023年
关键词
DDoS attack; Entropy; Internet of things; KL divergence; Security;
D O I
10.1109/WiMob58348.2023.10187726
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
High and low-volume Distributed Denial of Service (DDoS) attacks are critical threats to many Internet of Things (IoT) networks. Low-volume attacks gradually overwhelm the device's resources, whereas high-volume attacks suddenly flood the device's resources, causing a decline in Quality of Service (QoS). Researchers have proposed various methods to detect DDoS attacks based on statistical and Machine Learning (ML) approaches. Research has also shown that statistical approaches are more efficient for IoT networks as they are simpler to develop and have better real-time performance. However, most existing ML and statistical-based detection methods are effective for either high-volume or low-volume attacks but not for both. This paper proposes a novel Entropy and Divergence-based DDoS Attack Detection (EDDAD) system that uses a statistical approach to simultaneously detect high and low-volume DDoS attacks with high accuracy. The EDDAD system computes entropy and Kullback-Leibler (KL) divergence of flow features in a time window to detect malicious traffic in IoT networks with adaptive thresholds that utilize statistical information. Our analysis of experimental results from a real testbed demonstrated that the EDDAD system is effective and can achieve detection accuracy of greater than 90% for both high and low-volume DDoS attacks.
引用
收藏
页码:224 / 230
页数:7
相关论文
共 22 条
[1]   Statistical Application Fingerprinting for DDoS Attack Mitigation [J].
Ahmed, Muhammad Ejaz ;
Ullah, Saeed ;
Kim, Hyoungshick .
IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2019, 14 (06) :1471-1484
[2]   A Statistical Approach for Detection of Denial of Service Attacks in Computer Networks [J].
Amma, N. G. Bhuvaneswari ;
Selvakumar, S. ;
Velusamy, R. Leela .
IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2020, 17 (04) :2511-2522
[3]  
[Anonymous], 2019, U.S
[4]   Detection of DDoS attacks and flash events using novel information theory metrics [J].
Behal, Sunny ;
Kumar, Krishan .
COMPUTER NETWORKS, 2017, 116 :96-110
[5]  
Boddy S., 2017, F5 Labs Threat Anal. Rep, V3, P1
[6]   Timely Detection and Mitigation of Stealthy DDoS Attacks Via IoT Networks [J].
Doshi, Keval ;
Yilmaz, Yasin ;
Uludag, Suleyman .
IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2021, 18 (05) :2164-2176
[7]   Mathematical Approach as Qualitative Metrics of Distributed Denial of Service Attack Detection Mechanisms [J].
Ghaben, Ayman ;
Anbar, Mohammed ;
Hasbullah, Iznan Husainy ;
Karuppayah, Shankar .
IEEE ACCESS, 2021, 9 :123012-123028
[8]   IoT-KEEPER: Detecting Malicious IoT Network Activity Using Online Traffic Analysis at the Edge [J].
Hafeez, Ibbad ;
Antikainen, Markku ;
Ding, Aaron Yi ;
Tarkoma, Sasu .
IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2020, 17 (01) :45-59
[9]   Detecting HTTP-based application layer DoS attacks on web servers in the presence of sampling [J].
Jazi, Hossein Hadian ;
Gonzalez, Hugo ;
Stakhanova, Natalia ;
Ghorbani, Ali A. .
COMPUTER NETWORKS, 2017, 121 :25-36
[10]   Comprehensive Review of Artificial Intelligence and Statistical Approaches in Distributed Denial of Service Attack and Defense Methods [J].
Khalaf, Bashar Ahmed ;
Mostafa, Salama A. ;
Mustapha, Aida ;
Mohammed, Mazin Abed ;
Abduallah, Wafaa Mustafa .
IEEE ACCESS, 2019, 7 :51691-51713