Entropy Based Detection of DDoS Attacks in Packet Switching Network Models

被引:0
|
作者
Lawniczak, Anna T. [1 ]
Wu, Hao [1 ]
Di Stefano, Bruno [2 ]
机构
[1] Univ Guelph, Dept Math & Stat, Guelph, ON N1G 2W1, Canada
[2] Nuptek Syst Ltd, Toronto, ON M5R 3M6, Canada
来源
COMPLEX SCIENCES, PT 2 | 2009年 / 5卷
基金
加拿大自然科学与工程研究理事会;
关键词
distributed denial of service attack; packet switching network; entropy;
D O I
暂无
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Distributed denial-of-service (DDoS) attacks are network-wide attacks that cannot be detected or stopped easily. They affect "natural" spatio-temporal packet traffic patterns, i.e. "natural distributions" of packets passing through the routers. Thus, they affect "natural" information entropy profiles, a sort of "fingerprints", of normal packet traffic. We study if by monitoring information entropy of packet traffic through selected routers one may detect DDoS attacks or anomalous packet traffic in packet switching network (PSN) models. Our simulations show that the considered DDoS attacks of "ping" type cause shifts in information entropy profiles of packet traffic monitored even at small sets of routers and that it is easier to detect these shifts if static routing is used instead of dynamic routing. Thus, network-wide monitoring of information entropy of packet traffic at properly selected routers may provide means for detecting DDoS attacks and other anomalous packet traffics.
引用
收藏
页码:1810 / +
页数:2
相关论文
共 50 条
  • [21] Defending DDoS attacks using network traffic analysis and probabilistic packet drop
    Seo, J
    Lee, C
    Moon, J
    GRID AND COOPERATIVE COMPUTING GCC 2004 WORKSHOPS, PROCEEDINGS, 2004, 3252 : 390 - 397
  • [22] Branch label based probabilistic packet marking for counteracting DDoS attacks
    Ogawa, T
    Nakamura, F
    Wakahara, Y
    IEICE TRANSACTIONS ON COMMUNICATIONS, 2004, E87B (07) : 1900 - 1909
  • [23] Packet_In message based DDoS attack detection in SDN network using OpenFlow
    You, Xiang
    Feng, Yaokai
    Sakurai, Kouichi
    2017 FIFTH INTERNATIONAL SYMPOSIUM ON COMPUTING AND NETWORKING (CANDAR), 2017, : 522 - 528
  • [24] A Review on DDoS Attacks Classifying and Detection by ML/DL Models
    Alqahtani, Haya Malooh
    Abdullah, Monir
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2024, 15 (02) : 824 - 833
  • [25] On Selection of Attributes for Entropy Based Detection of DDoS
    Sharma, Sidharth
    Sahu, Santosh Kumar
    Jena, Sanjay Kumar
    2015 INTERNATIONAL CONFERENCE ON ADVANCES IN COMPUTING, COMMUNICATIONS AND INFORMATICS (ICACCI), 2015, : 1096 - 1100
  • [26] Collaborative detection of DDoS attacks over multiple network domains
    Chen, Yu
    Hwang, Kai
    Ku, Wei-Shinn
    IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2007, 18 (12) : 1649 - 1662
  • [27] Network Parameters Applicable in Detection of Infrastructure Level DDoS Attacks
    Cvitic, Ivan
    Perakovic, Dragan
    Perisa, Marko
    Musa, Mario
    2017 25TH TELECOMMUNICATION FORUM (TELFOR), 2017, : 310 - 313
  • [28] FireCol: A Collaborative Protection Network for the Detection of Flooding DDoS Attacks
    Francois, Jerome
    Aib, Issam
    Boutaba, Raouf
    IEEE-ACM TRANSACTIONS ON NETWORKING, 2012, 20 (06) : 1828 - 1841
  • [29] Neural Network-Based Approach for Detection and Mitigation of DDoS Attacks in SDN Environments
    Hannache, Oussama
    Batouche, Mohamed Chaouki
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY AND PRIVACY, 2020, 14 (03) : 50 - 71
  • [30] Distributed change detection for worms, DDoS and other network attacks
    Cardenas, AA
    Baras, JS
    Ramezani, V
    PROCEEDINGS OF THE 2004 AMERICAN CONTROL CONFERENCE, VOLS 1-6, 2004, : 1008 - 1013