Detection of DDoS attacks using optimized traffic matrix

被引:35
|
作者
Lee, Sang Min [3 ]
Kim, Dong Seong [1 ,2 ]
Lee, Je Hak [3 ]
Park, Jong Sou [3 ]
机构
[1] Univ Canterbury, Dept Comp Sci & Software Eng, Christchurch 1, New Zealand
[2] Duke Univ, Dept Elect & Comp Eng, Durham, NC USA
[3] Korea Aerosp Univ, Dept Comp Eng, Seoul, South Korea
关键词
DDoS attacks; Genetic algorithm; Intrusion detection; Traffic matrix;
D O I
10.1016/j.camwa.2011.08.020
中图分类号
O29 [应用数学];
学科分类号
070104 ;
摘要
Distributed Denial of Service (DDoS) attacks have been increasing with the growth of computer and network infrastructures in Ubiquitous computing. DDoS attacks generating mass traffic deplete network bandwidth and/or system resources. It is therefore significant to detect DDoS attacks in their early stage. Our previous approach used a traffic matrix to detect DDoS attacks quickly and accurately. However, it could not find out to tune up parameters of the traffic matrix including (i) size of traffic matrix. (ii) time based window size, and (iii) a threshold value of variance from packets information with respect to various monitored environments and DDoS attacks. Moreover, the time based window size led to computational overheads when DDoS attacks did not occur. To cope with it, we propose an enhanced DDoS attacks detection approach by optimizing the parameters of the traffic matrix using a Genetic Algorithm (GA) to maximize the detection rates. Furthermore, we improve the traffic matrix building operation by (i) reforming the hash function to decrease hash collisions and (ii) replacing the time based window size with a packet based window size to reduce the computational overheads. We perform experiments with DARPA 2000 LLDOS 1.0, LBL-PKT-4 of Lawrence Berkeley Laboratory and generated attack datasets. The experimental results show the feasibility of our approach in terms of detection accuracy and speed. (C) 2011 Elsevier Ltd. All rights reserved.
引用
收藏
页码:501 / 510
页数:10
相关论文
共 50 条
  • [21] Cooperative Mitigation of DDoS Attacks Using an Optimized Auction Scheme on Cache Servers
    Gulihar, Prachi
    Gupta, B. B.
    ADVANCED INFORMATICS FOR COMPUTING RESEARCH, PT II, 2019, 956 : 401 - 412
  • [22] VMFCVD: An Optimized Framework to Combat Volumetric DDoS Attacks using Machine Learning
    Arvind Prasad
    Shalini Chandra
    Arabian Journal for Science and Engineering, 2022, 47 : 9965 - 9983
  • [23] Traffic Monitoring and DDoS Detection using Stateful SDN
    Rebecchi, Filippo
    Boite, Julien
    Nardin, Pierre-Alexis
    Bouet, Mathieu
    Conan, Vania
    2017 IEEE CONFERENCE ON NETWORK SOFTWARIZATION (IEEE NETSOFT), 2017,
  • [24] Prevention of DDoS attacks using an optimized deep learning approach in blockchain technology
    Ilyas, Benkhaddra
    Kumar, Abhishek
    Setitra, Mohamed Ali
    Bensalem, ZineEl Abidine
    Lei, Hang
    TRANSACTIONS ON EMERGING TELECOMMUNICATIONS TECHNOLOGIES, 2023, 34 (04)
  • [25] Detection of DDoS Attacks in Software Defined Networking Using Entropy
    Fan, Cong
    Kaliyamurthy, Nitheesh Murugan
    Chen, Shi
    Jiang, He
    Zhou, Yiwen
    Campbell, Carlene
    APPLIED SCIENCES-BASEL, 2022, 12 (01):
  • [26] Early Detection of DDoS Attacks using Photonic Neural Networks
    Kirtas, M.
    Passalis, N.
    Kalavrouziotis, D.
    Syrivelis, D.
    Bakopoulos, P.
    Pleros, N.
    Tefas, A.
    2022 IEEE 14TH IMAGE, VIDEO, AND MULTIDIMENSIONAL SIGNAL PROCESSING WORKSHOP (IVMSP), 2022,
  • [27] Detection and Classification of DDoS Attacks Using Fuzzy Inference System
    Subbulakshmi, T.
    Shalinie, S. Mercy
    Reddy, C. Suneel
    Ramamoorthi, A.
    RECENT TRENDS IN NETWORK SECURITY AND APPLICATIONS, 2010, 89 : 242 - 252
  • [28] DDoS Attacks Detection and Mitigation in SDN using Machine Learning
    Rahman, Obaid
    Quraishi, Mohammad Ali Gauhar
    Lung, Chung-Horng
    2019 IEEE WORLD CONGRESS ON SERVICES (IEEE SERVICES 2019), 2019, : 184 - 189
  • [29] Study on Web DDOS Attacks Detection Using Multinomial Classifier
    Ajagekar, Shital K.
    Jadhav, Vaishali
    2016 IEEE INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND COMPUTING RESEARCH, 2016, : 866 - 870
  • [30] Effective DDoS Attacks Detection Using Generalized Entropy Metric
    Li, Ke
    Zhou, Wanlei
    Yu, Shui
    Dai, Bo
    ALGORITHMS AND ARCHITECTURES FOR PARALLEL PROCESSING, PROCEEDINGS, 2009, 5574 : 266 - +