DDoS Attack Detection using Fast Entropy Approach on Flow-Based Network Traffic

被引:76
作者
David, Jisa [1 ]
Thomas, Ciza [2 ]
机构
[1] Rajagiri Sch Engn & Technol, Dept Elect & Commun, Kochi 682039, Kerala, India
[2] Coll Engn, Dept Elect & Commun, Trivandrum 695016, Kerala, India
来源
BIG DATA, CLOUD AND COMPUTING CHALLENGES | 2015年 / 50卷
关键词
DDoS; Flow-based analysis; Fast Entropy;
D O I
10.1016/j.procs.2015.04.007
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Denial of service attack and Distributed Denial of Service attacks are becoming an increasingly frequent disturbance of the global Internet. In this paper we propose improvement in detection of Distributed Denial of Service attacks based on fast entropy method using flow-based analysis. An adaptive threshold algorithm is made use of since both network activities and user's behavior could vary over time. Fast Entropy and flow-based analysis show significant reduction in computational time compared to conventional entropy computation while maintaining good detection accuracy. The network traffic is analyzed and fast entropy of request per flow is calculated. DDoS attack is detected when the difference between entropy of flow count at each instant and mean value of entropy in that time interval is greater than the threshold value that is updated adaptively based on traffic pattern condition to improve the detection accuracy. (C) 2015 The Authors. Published by Elsevier B.V. This is an open access article under the CC BY-NC-ND license (http://creativecommons.org/licenses/by-nc-nd/4.0/).
引用
收藏
页码:30 / 36
页数:7
相关论文
共 8 条
[1]  
Cisar P., P 7 INT S HUNG RES C
[2]  
David Jisa, 2011, 1 INT C COMP SCI INF, P393
[3]  
Ditcheva T., 2005, SIGNATURE BASED INTR
[4]  
Giseop No, 2011, Proceedings of the 2011 Fifth International Conference on Innovative Mobile and Internet Services in Ubiquitous Computing (IMIS), P86, DOI 10.1109/IMIS.2011.82
[5]  
Hick Paul., the caida ddos attack 2007 dataset
[6]  
Jin Wang, 2010, 2010 IEEE Symposium on Computers and Communications (ISCC), P966, DOI 10.1109/ISCC.2010.5546587
[7]   Collaborative defense mechanism using statistical detection method against DDoS attacks [J].
Song, ByungHak ;
Heo, Joon ;
Hong, Choong Seon .
IEICE TRANSACTIONS ON COMMUNICATIONS, 2007, E90B (10) :2655-2664
[8]  
Specht SM, 2004, PARALLEL AND DISTRIBUTED COMPUTING SYSTEMS, P543