Efficient DDoS flood attack detection using dynamic thresholding on flow-based network traffic.
Computers & Security(2019)
摘要
Internet applications are used in various sectors as it contributes in enhancing the system usage in many respects. However, the interconnected computer systems and networks are vulnerable to very large number of attacks; Distributed Denial of Service being a major one. This paper analyses the features of network traffic and the existing algorithms to detect Distributed Denial of Service attacks and proposes an efficient statistical approach to detect the attacks based on traffic features and dynamic threshold detection algorithm. Dynamic threshold is made use of since both network activities and user’s behaviour could vary over time. The proposed algorithm extract different traffic features, calculate four attributes based on the characteristics of Distributed Denial of Service and the attack gets detected when the calculated attributes within a time interval is greater than the threshold value. MIT Lincoln Laboratory DARPA datasets and dataset developed in an university laboratory are used to validate the algorithm and the model proposed in this paper and also to measure the performance of the proposed approach. Experimental results demonstrate the improved performance of the proposed approach with significantly higher detection rate and accuracy and lesser processing time compared to the existing methods.
更多查看译文
关键词
DDoS attack,Network security,Dynamic threshold,Network traffic,Traffic features
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络