A Multimetric Approach for Discriminating Distributed Denial of Service Attacks from Flash Crowds

被引:1
作者
Elhadef, Mourad [1 ]
机构
[1] Abu Dhabi Univ, Coll Engn, Abu Dhabi, U Arab Emirates
来源
ADVANCED MULTIMEDIA AND UBIQUITOUS ENGINEERING: FUTURE INFORMATION TECHNOLOGY, VOL 2 | 2016年 / 354卷
关键词
DDoS attacks; Flash crowds; Similarity; Entropy; Information distance; Discrimination; DDOS ATTACKS; DEFENSE;
D O I
10.1007/978-3-662-47895-0_3
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Distributed Denial of Service (DDoS) attack, whether at the application or network layer, continues to be a critical threat to the Internet. In a DDoS attack, attackers run a massive number of queries through the victim's search engine or database query to bring the server down. This massive number of queries results in a very high traffic generated within a short period of time. Or in the Internet, researchers have identified a legitimate high traffic, known as a flash crow, where a very large number of users simultaneously access a popular web site, which produces a surge in traffic to the web site and might cause the site to be virtually unreachable. Thus the need to be able to discriminate between DDoS attack traffics and flash crowds. In this project, a hybrid discrimination mechanism is proposed to detect DDoS attacks using various features that characterize the DDoS traffics, and that distinguish it from flash crowds. These features include among others the entropy variation, the information distance, and the correlation coefficient.
引用
收藏
页码:17 / 23
页数:7
相关论文
共 23 条
[1]  
Barford P, 2002, IMW 2002: PROCEEDINGS OF THE SECOND INTERNET MEASUREMENT WORKSHOP, P71, DOI 10.1145/637201.637210
[2]  
Blazek R.B., 2001, Proceedings of IEEE systems, man and cybernetics information assurance workshop, P220
[3]   Denial-of-service attack-detection techniques [J].
Carl, G ;
Kesidis, G ;
Brooks, RR ;
Rai, S .
IEEE INTERNET COMPUTING, 2006, 10 (01) :82-89
[4]   Spectral analysis of TCP flows for defense against Reduction-of-Quality attacks [J].
Chen, Yu ;
Hwang, Kai .
2007 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, VOLS 1-14, 2007, :1203-+
[5]   Collaborative detection and filtering of shrew DDoS attacks using spectral analysis [J].
Chen, Yu ;
Hwang, Kai .
JOURNAL OF PARALLEL AND DISTRIBUTED COMPUTING, 2006, 66 (09) :1137-1151
[6]  
Duan Z., IEEE T DEPENDABLE SE, V5, P22
[7]   Statistical approaches to DDoS attack detection and response [J].
Feinstein, L ;
Schnackenberg, D ;
Balupari, R ;
Kindred, D .
DARPA INFORMATION SURVIVABILITY CONFERENCE AND EXPOSITION, VOL I, PROCEEDINGS, 2003, :303-314
[8]  
Jung J., 2002, Proc. of the International World Wide Web Conference, P252
[9]  
KANDULA S, 2005, P 2 S NETW SYST DES
[10]  
Kumar K., 2007, P INT C SIGN PROC CO, P331