返回
Low-rate DDoS attacks detection method using data compression and behavior divergence measurement
DOI:10.1016/j.cose.2020.102107.png)
摘要
En 中文
Distributed denial of service (DDoS) attacks have been a typical and extremely destructive threat to the Internet. DDoS attack detections suffer from the nonnegligible high complexity of massive traffic flow storage in the high-speed network. Besides, hidden low-rate DDoS (LDDoS) attacks evade the existing detection methods due to the similarity between LDDoS attack traffic and normal traffic. Focusing on these problems, this paper proposes a new low-rate DDoS attack detection method (LDDM) by designing the multidimensional sketch structure and novel measurement methods on network flows. First, the multidimensional sketch structure is designed to aggregate and compress network flows, which contributes to reduce the cost of data storage and enhance detection performance. Then, the improved behavior divergence measurement method based on daub 4 wavelet transform is proposed to calculate the energy percentage of each sketch divergence. This method obtains effective results in distinguishing the normal traffic and attack traffic. Furthermore, a modified weighted exponential moving average method is designed to construct the dynamic threshold of normal network. Meanwhile, a traffic freezing mechanism is proposed to ensure the standardization of the dynamic threshold. Finally, the effectiveness of the LDDM is evaluated using several real low-rate DDoS attack datasets. The comparisons with other methods illustrate our method has a lower false positive rate and false negative rate, as well as higher accuracy in the detection of stealthy low-rate DDoS attacks. (C) 2020 Elsevier Ltd. All rights reserved.
Keyword:
Network security
Low-rate DDoS attack detection
Multidimensional sketch structure
Behavior divergence measurement
Daub 4 wavelet transform
Dynamic threshold mechanism
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
C
IF:
5.4
论文数:
4.6K
被引数:
1.4W
机构
引用论文
Efficient DDoS flood attack detection using dynamic thresholding on flow-based network traffic基于流的网络流量动态阈值的高效DDoS洪水攻击检测
COMPUTERS & SECURITY
IF5.4
An information-theoretic method for the detection of anomalies in network traffic
COMPUTERS & SECURITY
IF5.4
Multi-level hybrid support vector machine and extreme learning machine based on modified K-means for intrusion detection system基于改进k-means的多级混合支持向量机和极限学习机在入侵检测系统中的应用

