Entropy Based Detection of DDoS Attacks in Packet Switching Network Models

被引:0
|
作者
Lawniczak, Anna T. [1 ]
Wu, Hao [1 ]
Di Stefano, Bruno [2 ]
机构
[1] Univ Guelph, Dept Math & Stat, Guelph, ON N1G 2W1, Canada
[2] Nuptek Syst Ltd, Toronto, ON M5R 3M6, Canada
来源
COMPLEX SCIENCES, PT 2 | 2009年 / 5卷
基金
加拿大自然科学与工程研究理事会;
关键词
distributed denial of service attack; packet switching network; entropy;
D O I
暂无
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Distributed denial-of-service (DDoS) attacks are network-wide attacks that cannot be detected or stopped easily. They affect "natural" spatio-temporal packet traffic patterns, i.e. "natural distributions" of packets passing through the routers. Thus, they affect "natural" information entropy profiles, a sort of "fingerprints", of normal packet traffic. We study if by monitoring information entropy of packet traffic through selected routers one may detect DDoS attacks or anomalous packet traffic in packet switching network (PSN) models. Our simulations show that the considered DDoS attacks of "ping" type cause shifts in information entropy profiles of packet traffic monitored even at small sets of routers and that it is easier to detect these shifts if static routing is used instead of dynamic routing. Thus, network-wide monitoring of information entropy of packet traffic at properly selected routers may provide means for detecting DDoS attacks and other anomalous packet traffics.
引用
收藏
页码:1810 / +
页数:2
相关论文
共 50 条
  • [1] IP packet size entropy-based scheme for detection of DoS/DDoS attacks
    Du, Ping
    Abe, Shunji
    IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2008, E91D (05) : 1274 - 1281
  • [2] Entropy-Based Collaborative Detection of DDOS Attacks on Community Networks
    Yu, Shui
    Zhou, Wanlei
    2008 IEEE INTERNATIONAL CONFERENCE ON PERVASIVE COMPUTING AND COMMUNICATIONS, 2008, : 566 - 571
  • [3] Early Detection of Campus Network DDoS Attacks using Predictive Models
    Araki, Ryusei
    Hsu, Ying-Feng
    Matsuoka, Morito
    2022 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM 2022), 2022, : 3362 - 3367
  • [4] Resisting network DDoS attacks by packet asymmetry path marking
    Jin, Guang
    Yang, Jiangang
    Wei, Wei
    Dong, Yabo
    2007 SECOND INTERNATIONAL CONFERENCE IN COMMUNICATIONS AND NETWORKING IN CHINA, VOLS 1 AND 2, 2007, : 363 - 367
  • [5] Entropy Methods for DDoS Attacks Detection in Telecommunication Systems
    Popovskyy, Vladimir
    Skibin, Vladislav
    2014 FIRST INTERNATIONAL SCIENTIFIC-PRACTICAL CONFERENCE PROBLEMS OF INFOCOMMUNICATIONS SCIENCE AND TECHNOLOGY (PIC S&T), 2014, : 182 - 185
  • [6] Performance analysis of entropy variation-based detection of DDoS attacks in IoT
    Pandey, Nimisha
    Mishra, Pramod Kumar
    INTERNET OF THINGS, 2023, 23
  • [7] DDoS Attacks Detection by Means of Statistical Models
    Andrysiak, Tomasz
    Saganowski, Lukasz
    PROCEEDINGS OF THE 9TH INTERNATIONAL CONFERENCE ON COMPUTER RECOGNITION SYSTEMS, CORES 2015, 2016, 403 : 797 - 806
  • [8] Detection DDoS of Attacks Based on Federated Learning with Digital Twin Network
    Su, Dingling
    Qu, Zehui
    KNOWLEDGE SCIENCE, ENGINEERING AND MANAGEMENT, KSEM 2022, PT III, 2022, 13370 : 153 - 164
  • [9] Chaos Theory Based Detection against Network Mimicking DDoS Attacks
    Chonka, Ashley
    Singh, Jaipal
    Zhou, Wanlei
    IEEE COMMUNICATIONS LETTERS, 2009, 13 (09) : 717 - 719
  • [10] Detection of DDoS Attacks in Software Defined Networking Using Entropy
    Fan, Cong
    Kaliyamurthy, Nitheesh Murugan
    Chen, Shi
    Jiang, He
    Zhou, Yiwen
    Campbell, Carlene
    APPLIED SCIENCES-BASEL, 2022, 12 (01):