arrow
Return

Efficient DDoS flood attack detection using dynamic thresholding on flow-based network traffic

delete2019-05-01
delete76
PRE
AI
J
Jisa David *
C
Ciza Thomas
DOI:10.1016/j.cose.2019.01.002delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Internet applications are used in various sectors as it contributes in enhancing the system usage in many respects. However, the interconnected computer systems and networks are vulnerable to very large number of attacks; Distributed Denial of Service being a major one. This paper analyses the features of network traffic and the existing algorithms to detect Distributed Denial of Service attacks and proposes an efficient statistical approach to detect the attacks based on traffic features and dynamic threshold detection algorithm. Dynamic threshold is made use of since both network activities and user's behaviour could vary over time. The proposed algorithm extract different traffic features, calculate four attributes based on the characteristics of Distributed Denial of Service and the attack gets detected when the calculated attributes within a time interval is greater than the threshold value. MIT Lincoln Laboratory DARPA datasets and dataset developed in an university laboratory are used to validate the algorithm and the model proposed in this paper and also to measure the performance of the proposed approach. Experimental results demonstrate the improved performance of the proposed approach with significantly higher detection rate and accuracy and lesser processing time compared to the existing methods. (C) 2019 Elsevier Ltd. All rights reserved.
Keywords:
DDoS attack
Network security
Dynamic threshold
Network traffic
Traffic features

Journal

C
Computers and Security
IF:
5.4
Papers:
4.6K
Citations:
1.4W

Organization

R
rajagiri school of engineering & technology
Scholars:
101
Papers: 80
Citations: 0
C
college of engineering, trivandrum
Scholars:
335
Papers: 234
Citations: 0
Cited Papers

Cited Papers

errShare
errSave
errShare
errSave
errShare
errSave
A framework for generating realistic traffic for Distributed Denial-of-Service attacks and Flash Events
err2014-02-01
err39
PREAI
errBhatia, Sajal; Schmidt, Desmond; Mohay, George; Tickle, Alan
errShare
errSave
errShare
errSave
researcher View more