Probability principle of a reliable approach to detect signs of DDOS flood attacks

被引:0
作者
Li, M [1 ]
Liu, JG [1 ]
Long, DY [1 ]
机构
[1] Zhongshan Univ, Dept Comp Sci, Guangzhou 510275, Peoples R China
来源
PARALLEL AND DISTRIBUTED COMPUTING: APPLICATIONS AND TECHNOLOGIES, PROCEEDINGS | 2004年 / 3320卷
关键词
anomaly intrusion detection; intrusion prevention; DDOS; statistical detection; probability; reliability;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Attentions are increasingly paid to reliable detection of intrusions as can be seen from [1, 2]. As a matter of fact, the challenge is to develop a system that detects close to 100 percent of attacks with minimal false positives. We are still far from achieving this goal [1, p. 28]. In this regard, our early work discusses a reliable approach regarding detection of signs of distributed denial-of-service (DDOS) attacks [3], where arrival time series of a protected site is specifically featured by autocorrelation function. As a supplementary to [31, this article specifically focuses on abstractly discussing probability principle involved in [3] such that the present probability principle of detection is flexible in practical applications. In addition to this, the selection of a threshold for a given detection probability is also given.
引用
收藏
页码:596 / 599
页数:4
相关论文
共 16 条
[1]   Traffic models in broadband networks [J].
Adas, A .
IEEE COMMUNICATIONS MAGAZINE, 1997, 35 (07) :82-89
[2]  
AMOROSO E, 1999, INTRO INTERNET SURVE
[3]  
BENDAT JS, 2000, RANDOM DAT ANAL MEAS
[4]   Denial-of-service attacks rip the Internet [J].
Garber, L .
COMPUTER, 2000, 33 (04) :12-17
[5]  
Griffel D.H., 1981, APPL FUNCTIONAL ANAL
[6]  
KEMMERER RA, 2002, SUPPLEMENT COMPUTER, V35, P27
[7]   Improving user security behaviour [J].
Leach, J .
COMPUTERS & SECURITY, 2003, 22 (08) :685-692
[8]  
LEVYVEHEL J, 1997, FRACTALS ENG SPRINGE
[9]   Correlation form of timestamp increment sequences of self-similar traffic on Ethernet [J].
Li, M ;
Jia, WJ ;
Zhao, W .
ELECTRONICS LETTERS, 2000, 36 (19) :1668-1669
[10]   Modeling autocorrelation functions of self-similar teletraffic in communication networks based on optimal approximation in Hilbert space [J].
Li, M ;
Zhao, W ;
Jia, WJ ;
Long, PY ;
Chi, CH .
APPLIED MATHEMATICAL MODELLING, 2003, 27 (03) :155-168