arrow
Return

Lightweight DDoS Attack Detection Using Bayesian Space-Time Correlation

delete2025-01-01
delete0
delete
OA
AI
G
Gabriel Mendonça
R
Rosa M. M. Leão *
E
Edmundo de Souza e Silva
D
Don Towsley
DOI:10.1109/ACCESS.2025.3553742delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
DDoS attacks are still one of the primary sources of problems on the Internet and continue to cause significant financial losses for organizations. To mitigate their impact, detection should preferably occur close to the attack origin, e.g., at home routers or edge servers. However, relying on packet inspection may bring serious privacy and scalability issues. We propose a lightweight system for DDoS detection that solely employs byte and packet counts from off-the-shelf home routers. To detect attacks with such a limited amount of information, our key insight consists in defining two detection layers: 1) a ML classifier trained with data from real home user and malware; 2) and a Bayesian hierarchical model that exploits the synchronized nature of DDoS attacks by correlating alarms from multiple homes to check the approach in the wild. We collect data on DDoS attacks by generating real attack traffic from the homes of a selected group of volunteers, utilizing authentic malware source code. In that experiment, conducted using the residences of volunteers and over one month, our system detected 99.1% of all DDoS attacks launched, with no false alarms.
Keywords:
Denial-of-service attack
Internet of Things
Computer crime
Bayes methods
Detectors
Correlation
Botnet
Servers
Malware
Vectors
DDoS attacks
network security
Mirai botnet
machine learning algorithms
IoT
Bayesian model
network traffic measurements

Journal

IEEE Access cover
IEEE Access
IF:
3.6
Papers:
9.7W
Citations:
29.4W

Organization

U
university of massachusetts system
Scholars:
3.8W
Papers: 3.5W
Citations: 42
U
Universidade Federal do Rio de Janeiro
Scholars:
2.9W
Papers: 1.8W
Citations: 1.6W