An anomaly based distributed detection system for DDoS attacks in Tier-2 ISP networks

被引:7
作者
Bhandari, Abhinav [1 ]
Kumar, Krishan [2 ]
Sangal, A. L. [3 ]
Behal, Sunny [4 ]
机构
[1] Punjabi Univ, Patiala, Punjab, India
[2] UIET Panjab Univ, Chandigarh, India
[3] Dr BR Ambedkar NIT, Jalandhar, Punjab, India
[4] SBS State Tech Campus, Ferozepur, Punjab, India
关键词
DDoS attacks; Network security; Entropy; Information divergence; Flash events; Detection; DIVERGENCE MEASURES; DEFENSE; SERVICE;
D O I
10.1007/s12652-020-02208-3
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
In the present computer era, the vulnerabilities inherent in the Internet architecture enable various kinds of attacks. Distributed Denial of Service (DDoS) is one of such prominent attack that is a lethal threat to Internet domain that harnesses its computing and communication resources. The increase in network traffic rates of legitimate traffic and its flow similarity with attack traffic has made the DDoS detection very difficult despite deployment of diversified defense solutions. The ISPs are bound to invest heavily to counter such problems which has a significant impact on company finances. To provide uninterrupted quality services to the end users, ISPs needs to deploy a distributed solution for timely detection and discrimination of attack and behaviorally similar flash events (FE) traffic. Such distributed defense systems can be deployed at source-end, intermediate network-end or at the victim-end location. Since the volume of traffic to be analyzed is very large, the detection accuracy and low computational complexity of the proposed defense solution is always a challenging problem. This paper proposes an ISP level distributed, collaborative and automated (D-CAD) defense system for detecting DDoS attacks and FEs, and has the capability to effectively distinguishing the two. Additionally, D-CAD defense system is also capable of categorizing FE traffic and has low computational complexity. The proposed system is validated in novel software defined networks (SDN) using Mininet emulator. The results show that D-CAD defense system outperformed its existing counterparts on various detection system evaluation metrics.
引用
收藏
页码:1387 / 1406
页数:20
相关论文
共 50 条
[1]  
[Anonymous], 2019, TECH REP
[2]  
[Anonymous], 2012, ARXIV PREPRINT ARXIV
[3]  
[Anonymous], 2019, EVID BASED COMPLEMEN
[4]  
[Anonymous], P 20 ANN NETWORK DIS
[5]  
[Anonymous], 2008, INT C INF SEC
[6]  
[Anonymous], 2016, NDSS
[7]  
Barford P, 2001, IMW 2001: PROCEEDINGS OF THE FIRST ACM SIGCOMM INTERNET MEASUREMENT WORKSHOP, P69
[8]   SEAL: SDN based secure and agile framework for protecting smart city applications from DDoS attacks [J].
Bawany, Narmeen Zakaria ;
Shamsi, Jawwad A. .
JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2019, 145
[9]   Discriminating flash events from DDoS attacks: A comprehensive review [J].
Behal S. ;
Kumar K. ;
Sachdeva M. .
International Journal of Network Security, 2017, 19 (05) :734-741
[10]   D-FACE: An anomaly based distributed approach for early detection of DDoS attacks and flash events [J].
Behal, Sunny ;
Kumar, Krishan ;
Sachdeva, Monika .
JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2018, 111 :49-63