IP packet size entropy-based scheme for detection of DoS/DDoS attacks

被引:18
作者
Du, Ping [1 ]
Abe, Shunji [1 ]
机构
[1] Natl Inst Informat, Tokyo 1018430, Japan
关键词
denial of service attack; network security; attack detection;
D O I
10.1093/ietisy/e91-d.5.1274
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Denial of service (DoS) attacks have become one of the most serious threats to the Internet. Enabling detection of attacks in network traffic is an important and challenging task. However, most existing volume-based schemes can not detect short-term attacks that have a minor effect on traffic volume. On the other hand, feature-based schemes are not suitable for real-time detection because of their complicated calculations. In this paper, we develop an IP packet size entropy (IPSE)-based DoS/DDoS detection scheme in which the entropy is markedly changed when traffic is affected by an attack. Through our analysis, we find that the IPSE-based scheme is capable of detecting not only long-term attacks but also short-term attacks that are beyond the volume-based schemes' ability to detect. Moreover, we test our proposal using two typical Internet traffic data sets from DARPA and SINET, and the test results show that the IPSE-based detection scheme can provide detection of DoS/DDoS attacks not only in a local area network (DARPA) and but also in academic backbone network (SINET).
引用
收藏
页码:1274 / 1281
页数:8
相关论文
共 17 条
[11]   DDoS attack detection and wavelets [J].
Li, L ;
Lee, G .
ICCCN 2003: 12TH INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATIONS AND NETWORKS, PROCEEDINGS, 2003, :421-427
[12]   The 1999 DARPA off-line intrusion detection evaluation [J].
Lippmann, R ;
Haines, JW ;
Fried, DJ ;
Korba, J ;
Das, K .
COMPUTER NETWORKS-THE INTERNATIONAL JOURNAL OF COMPUTER AND TELECOMMUNICATIONS NETWORKING, 2000, 34 (04) :579-595
[13]  
SEKAR R, 2002, P ACM CCS
[14]  
Siris VA, 2004, GLOB TELECOMM CONF, P2050
[15]  
Vigna G., 1999, Journal of Computer Security, V7, P37
[16]  
WALFISH M, P ACM SIGCOMM 2006
[17]  
Wang HI, 2002, IEEE INFOCOM SER, P1530, DOI 10.1109/INFCOM.2002.1019404