Change-point monitoring for the detection of DoS attacks

被引:92
|
作者
Wang, HN
Zhang, DL
Shin, KG
机构
[1] Coll William & Mary, Dept Comp Sci, Williamsburg, VA 23187 USA
[2] Qualcomm inc, Corp Res & Dev, San Diego, CA 92122 USA
[3] Univ Michigan, Dept Elect Engn & Comp Sci, Real Time Comp Lab, Ann Arbor, MI 48109 USA
基金
美国国家科学基金会;
关键词
CUSUM algorithm; DoS attacks; intrusion detection; protocol behavior;
D O I
10.1109/TDSC.2004.34
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
This paper presents a simple and robust mechanism, called Change-Point Monitoring (CPM), to detect denial of service (DoS) attacks. The core of CPM is based on the inherent network protocol behaviors and is an instance of the Sequential Change Point Detection. To make the detection mechanism insensitive to sites and traffic patterns, a nonparametric Cumulative Sum (CUSUM) method is applied, thus making the detection mechanism robust, more generally applicable, and its deployment much easier. CPM does not require per-flow state information and only introduces a few variables to record the protocol behaviors., The statelessness and low computation overhead of CPM make itself immune to any flooding attacks. As a case study, the efficacy of CPM is evaluated by detecting a SYN flooding attack-the most common DoS attack. The evaluation results show that CPM has short detection latency and high detection accuracy.
引用
收藏
页码:193 / 208
页数:16
相关论文
共 50 条
  • [1] A novel framework of change-point detection for machine monitoring
    Lu, Guoliang
    Zhou, Yiqi
    Lu, Changhou
    Li, Xueyong
    [J]. MECHANICAL SYSTEMS AND SIGNAL PROCESSING, 2017, 83 : 533 - 548
  • [2] Detection of (D)DOS Attacks Based on Online Change Point Analysis
    Semerci, Murat
    Yamac, Mehmet
    Cemgil, Ali Taylan
    Sankur, Bulent
    Cosar, Derya Selin
    [J]. 2016 24TH SIGNAL PROCESSING AND COMMUNICATION APPLICATION CONFERENCE (SIU), 2016, : 1161 - 1164
  • [3] Water quality monitoring with online change-point detection methods
    Ba, Amadou
    McKenna, Sean A.
    [J]. JOURNAL OF HYDROINFORMATICS, 2015, 17 (01) : 7 - 19
  • [4] Algebraic change-point detection
    Michel Fliess
    Cédric Join
    Mamadou Mboup
    [J]. Applicable Algebra in Engineering, Communication and Computing, 2010, 21 : 131 - 143
  • [5] Algebraic change-point detection
    Fliess, Michel
    Join, Cedric
    Mboup, Mamadou
    [J]. APPLICABLE ALGEBRA IN ENGINEERING COMMUNICATION AND COMPUTING, 2010, 21 (02) : 131 - 143
  • [6] Active Change-Point Detection
    Hayashi, Shogo
    Kawahara, Yoshinobu
    Kashima, Hisashi
    [J]. ASIAN CONFERENCE ON MACHINE LEARNING, VOL 101, 2019, 101 : 1017 - 1032
  • [7] Active change-point detection
    Hayashi, Shogo
    Kawahara, Yoshinobu
    Kashima, Hisashi
    [J]. Transactions of the Japanese Society for Artificial Intelligence, 2020, 35 (05) : 1 - 10
  • [8] FRECHET CHANGE-POINT DETECTION
    Dubey, Paromita
    Mueller, Hans-Georg
    [J]. ANNALS OF STATISTICS, 2020, 48 (06): : 3312 - 3335
  • [9] CHANGE-POINT PROBLEMS IN EEG MONITORING
    MOLINARI, L
    DUMERMUTH, G
    [J]. ELECTROENCEPHALOGRAPHY AND CLINICAL NEUROPHYSIOLOGY, 1987, 66 (04): : P72 - P72
  • [10] Change-point monitoring in linear models
    Aue, Alexander
    Horvath, Lajos
    Huskova, Marie
    Kokoszka, Piotr
    [J]. ECONOMETRICS JOURNAL, 2006, 9 (03): : 373 - 403