共 35 条
Generalized Network Temperature for DDoS Detection through Renyi Entropy
被引:2
|作者:
Wang, Xiang
[1
]
Zhang, Xing
[1
]
Wang, Changda
[1
]
机构:
[1] Jiangsu Univ, Zhenjiang, Jiangsu, Peoples R China
来源:
2022 IEEE 22ND INTERNATIONAL CONFERENCE ON SOFTWARE QUALITY, RELIABILITY, AND SECURITY COMPANION, QRS-C
|
2022年
关键词:
network anomaly detection;
generalized network temperature;
EWMA;
SOFTWARE-DEFINED NETWORKING;
ATTACKS;
D O I:
10.1109/QRS-C57518.2022.00014
中图分类号:
TP31 [计算机软件];
学科分类号:
081202 ;
0835 ;
摘要:
Distributed Denial-of-Services (DDoS) are serious network threats hardly eliminated. Current network entropy-based DDoS detection methods suffer from distinguishing DDoS attack traffic among normal traffic through a fixed empirical detection threshold, i.e., most of such thresholds are case-sensitive ones. With the Renyi entropy of a network, the paper devised a Generalized Network Temperature (GNT) based approach for DDoS attack detection, where GNT is a novel and fine-granular-scale statistical indicator that describes the network entropy changes in the light of both network traffic and network topology changes. Within a series of predefined time windows, our proposed approach first collects the selected network traffic features and then calculates the GNT for each time window. Second, the DDoS attacks are then acknowledged or denied by comparing each GNT to a dynamically adjustable threshold generated by the Exponentially Weighted Moving Average (EWMA) model. Furthermore, the publicly available CIC DoS 2017 dataset is utilized to test the proposed approach in the paper. The experimental results show that our proposed approach outperforms the known Shannon entropy-based DDoS attack detection methods with respect to both efficacy and efficiency.
引用
收藏
页码:24 / 33
页数:10
相关论文