arrow
返回

Low-rate DDoS attacks detection method using data compression and behavior divergence measurement

delete2021-01-01
delete32
PRE
AI
X
Xinqian Liu
任
任家东 (Jiadong Ren) *
H
Haitao He
王茜 封面图
王茜 (Qian Wang)
C
Chen Song
DOI:10.1016/j.cose.2020.102107delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Distributed denial of service (DDoS) attacks have been a typical and extremely destructive threat to the Internet. DDoS attack detections suffer from the nonnegligible high complexity of massive traffic flow storage in the high-speed network. Besides, hidden low-rate DDoS (LDDoS) attacks evade the existing detection methods due to the similarity between LDDoS attack traffic and normal traffic. Focusing on these problems, this paper proposes a new low-rate DDoS attack detection method (LDDM) by designing the multidimensional sketch structure and novel measurement methods on network flows. First, the multidimensional sketch structure is designed to aggregate and compress network flows, which contributes to reduce the cost of data storage and enhance detection performance. Then, the improved behavior divergence measurement method based on daub 4 wavelet transform is proposed to calculate the energy percentage of each sketch divergence. This method obtains effective results in distinguishing the normal traffic and attack traffic. Furthermore, a modified weighted exponential moving average method is designed to construct the dynamic threshold of normal network. Meanwhile, a traffic freezing mechanism is proposed to ensure the standardization of the dynamic threshold. Finally, the effectiveness of the LDDM is evaluated using several real low-rate DDoS attack datasets. The comparisons with other methods illustrate our method has a lower false positive rate and false negative rate, as well as higher accuracy in the detection of stealthy low-rate DDoS attacks. (C) 2020 Elsevier Ltd. All rights reserved.
Keyword:
Network security
Low-rate DDoS attack detection
Multidimensional sketch structure
Behavior divergence measurement
Daub 4 wavelet transform
Dynamic threshold mechanism
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

C
Computers and Security
IF:
5.4
论文数:
4.6K
被引数:
1.4W

机构

Y
Yanshan University
学者数:
1.7W
论文数: 1.1W
被引数: 1.3W
引用论文

引用论文

An early detection of low rate DDoS attack to SDN based data center networks using information distance metrics
err2018-12-01
err122
PREAI
errSahoo, Kshira Sagar; Puthal, Deepak; Tiwary, Mayank; Rodrigues, Joel J. P. C.; Sahoo, Bibhudatta; Dash, Ratnakar
err分享
err收藏
An information-theoretic method for the detection of anomalies in network traffic
err2017-09-01
err22
errOAAI
errCallegari, Christian; Giordano, Stefano; Pagano, Michele
err分享
err收藏
err分享
err收藏
Management of Upper Extremity Vascular Injury: Outcome Related to the Mangled Extremity Severity Score
err2009-02-03
err0
PREAI
errSupparerk Prichayudh; Aumpavan Verananvattna; Suvit Sriussadaporn; Sukanya Sriussadaporn; Kritaya Kritayakirana; Rattaplee Pak‐art; Allan Capin; Bruno Pereira; Taichiro Tsunoyama; Diego Pena
err分享
err收藏
Post-fire water-quality response in the western United States
err2018-01-01
err0
PREAI
errAshley J. Rust; Terri S. Hogue; Samuel Saxe; John McCray
err分享
err收藏
学者 查看更多内容