Generalized Network Temperature for DDoS Detection through Renyi Entropy

被引:2
|
作者
Wang, Xiang [1 ]
Zhang, Xing [1 ]
Wang, Changda [1 ]
机构
[1] Jiangsu Univ, Zhenjiang, Jiangsu, Peoples R China
来源
2022 IEEE 22ND INTERNATIONAL CONFERENCE ON SOFTWARE QUALITY, RELIABILITY, AND SECURITY COMPANION, QRS-C | 2022年
关键词
network anomaly detection; generalized network temperature; EWMA; SOFTWARE-DEFINED NETWORKING; ATTACKS;
D O I
10.1109/QRS-C57518.2022.00014
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Distributed Denial-of-Services (DDoS) are serious network threats hardly eliminated. Current network entropy-based DDoS detection methods suffer from distinguishing DDoS attack traffic among normal traffic through a fixed empirical detection threshold, i.e., most of such thresholds are case-sensitive ones. With the Renyi entropy of a network, the paper devised a Generalized Network Temperature (GNT) based approach for DDoS attack detection, where GNT is a novel and fine-granular-scale statistical indicator that describes the network entropy changes in the light of both network traffic and network topology changes. Within a series of predefined time windows, our proposed approach first collects the selected network traffic features and then calculates the GNT for each time window. Second, the DDoS attacks are then acknowledged or denied by comparing each GNT to a dynamically adjustable threshold generated by the Exponentially Weighted Moving Average (EWMA) model. Furthermore, the publicly available CIC DoS 2017 dataset is utilized to test the proposed approach in the paper. The experimental results show that our proposed approach outperforms the known Shannon entropy-based DDoS attack detection methods with respect to both efficacy and efficiency.
引用
收藏
页码:24 / 33
页数:10
相关论文
共 35 条
  • [1] A low-rate DDoS detection and mitigation for SDN using Renyi Entropy with Packet Drop
    Ahalawat, Anchal
    Babu, Korra Sathya
    Turuk, Ashok Kumar
    Patel, Sanjeev
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2022, 68
  • [2] On Selection of Attributes for Entropy Based Detection of DDoS
    Sharma, Sidharth
    Sahu, Santosh Kumar
    Jena, Sanjay Kumar
    2015 INTERNATIONAL CONFERENCE ON ADVANCES IN COMPUTING, COMMUNICATIONS AND INFORMATICS (ICACCI), 2015, : 1096 - 1100
  • [3] DDoS Attack Detection Scheme Based on Entropy and PSO-BP Neural Network in SDN
    Zhenpeng Liu
    Yupeng He
    Wensheng Wang
    Bin Zhang
    中国通信, 2019, 16 (07) : 144 - 155
  • [4] DDoS Attack Detection Scheme Based on Entropy and PSO-BP Neural Network in SDN
    Liu, Zhenpeng
    He, Yupeng
    Wang, Wensheng
    Zhang, Bin
    CHINA COMMUNICATIONS, 2019, 16 (07) : 144 - 155
  • [5] Cusum - Entropy: An efficient method for DDoS attack detection
    Ozcelik, Ilker
    Brooks, Richard R.
    2016 4TH INTERNATIONAL ISTANBUL SMART GRID CONGRESS AND FAIR (ICSG), 2016, : 85 - 89
  • [6] Detection of DDoS Attacks in Software Defined Networking Using Entropy
    Fan, Cong
    Kaliyamurthy, Nitheesh Murugan
    Chen, Shi
    Jiang, He
    Zhou, Yiwen
    Campbell, Carlene
    APPLIED SCIENCES-BASEL, 2022, 12 (01):
  • [7] Network Anomaly Early Warning through Generalized Network Temperature and Deep Learning
    Yufan Feng
    Changda Wang
    Journal of Network and Systems Management, 2023, 31
  • [8] Network Anomaly Early Warning through Generalized Network Temperature and Deep Learning
    Feng, Yufan
    Wang, Changda
    JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2023, 31 (02)
  • [9] Conditional entropy-based hybrid DDoS detection model for IoT networks
    Pandey, Nimisha
    Mishra, Pramod Kumar
    COMPUTERS & SECURITY, 2025, 150
  • [10] Renyi Joint Entropy-Based Dynamic Threshold Approach to Detect DDoS Attacks against SDN Controller with Various Traffic Rates
    Aladaileh, Mohammad Adnan
    Anbar, Mohammed
    Hintaw, Ahmed J.
    Hasbullah, Iznan H.
    Bahashwan, Abdullah Ahmed
    Al-Sarawi, Shadi
    APPLIED SCIENCES-BASEL, 2022, 12 (12):