A TRAFFIC COHERENCE ANALYSIS MODEL FOR DDOS ATTACK DETECTION

被引:0
|
作者
Rahmani, Hamza [1 ]
Sahli, Nabil [1 ]
Kammoun, Farouk [1 ]
机构
[1] Natl Sch Comp Sci, CRISTAL Lab, Manouba 2010, Tunisia
来源
SECRYPT 2009: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON SECURITY AND CRYPTOGRAPHY | 2009年
关键词
Distributed denial of service; Probability distribution; Joint probability; Stochastic process; Central limit theorem;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Distributed Denial of Service (DDoS) attack is a critical threat to the Internet by severely degrading its performance. DDoS attack can be considered a system anomaly or misuse from which abnormal behaviour is imposed on network traffic. Network traffic characterization with behaviour modelling could be a good indication of attack detection witch can be performed via abnormal behaviour identification. In this paper, we will focus on the design and evaluation of the statistically automated attack detection. Our key idea is that contrary to DDoS traffic, flash crowd is characterized by a large increase not only in the number of packets but also in the number of IP connexions. The joint probability between the packet arrival process and the number of IP connexions process presents a good estimation of the degree of coherence between these two processes. Statistical distances between an observation and a reference time windows are computed for joint probability values. We show and illustrate that anomalously large values observed on these distances betray major changes in the statistics of Internet time series and correspond to the occurrences of illegitimate anomalies.
引用
收藏
页码:148 / 154
页数:7
相关论文
共 50 条
  • [1] Joint Entropy Analysis Model for DDoS Attack Detection
    Rahmani, Hamza
    Sahli, Nabil
    Kammoun, Farouk
    FIFTH INTERNATIONAL CONFERENCE ON INFORMATION ASSURANCE AND SECURITY, VOL 2, PROCEEDINGS, 2009, : 267 - 271
  • [2] System for DDoS attack mitigation by discovering the attack vectors through statistical traffic analysis
    Mirchev M.J.
    Mirtchev S.T.
    International Journal of Information and Computer Security, 2020, 13 (3-4) : 309 - 321
  • [3] DDoS Attack Detection and Wavelets
    Lan Li
    Gyungho Lee
    Telecommunication Systems, 2005, 28 : 435 - 451
  • [4] DDoS attack detection and wavelets
    Li, L
    Lee, GG
    TELECOMMUNICATION SYSTEMS, 2005, 28 (3-4) : 435 - 451
  • [5] DDoS Attack Detection Method Based on Linear Prediction Model
    Cheng, Jieren
    Yin, Jianping
    Wu, Chengkun
    Zhang, Boyun
    Liu, Yun
    EMERGING INTELLIGENT COMPUTING TECHNOLOGY AND APPLICATIONS, PROCEEDINGS, 2009, 5754 : 1004 - +
  • [6] DDoS attack detection and defense based on hybrid deep learning model in SDN
    Li C.
    Wu Y.
    Qian Z.
    Sun Z.
    Wang W.
    2018, Editorial Board of Journal on Communications (39): : 176 - 187
  • [7] Ensemble-based Model for DDoS Attack Detection and Flash Event Separation
    Bhatia, Sajal
    PROCEEDINGS OF 2016 FUTURE TECHNOLOGIES CONFERENCE (FTC), 2016, : 958 - 967
  • [8] An Experience Report on Scalable Implementation of DDoS Attack Detection
    Dorbala, Yogesh
    Kishore, R.
    Hubballi, Neminath
    ADVANCED INFORMATION SYSTEMS ENGINEERING WORKSHOPS, CAISE 2015, 2015, 215 : 518 - 529
  • [9] FLAD: Adaptive Federated Learning for DDoS attack detection
    Doriguzzi-Corin, Roberto
    Siracusa, Domenico
    COMPUTERS & SECURITY, 2024, 137
  • [10] Study on Detection Algorithm of DDoS Attack for Cloud Computing
    Luo Ya-dong
    2014 Fifth International Conference on Intelligent Systems Design and Engineering Applications (ISDEA), 2014, : 950 - 953