Detecting Distributed Denial of Service (DDoS) attacks through inductive learning

被引:0
|
作者
Noh, S [1 ]
Lee, C
Choi, K
Jung, GH
机构
[1] Catholic Univ Korea, Sch Comp Sci & Informat Engn, Bucheon, South Korea
[2] Ajou Univ, Grad Sch Informat & Commun, Suwon 441749, South Korea
[3] Ajou Univ, Div Elect Engn, Suwon 441749, South Korea
关键词
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
As the complexity of Internet is scaled up, it is likely for the Internet resources to be exposed to Distributed Denial of Service (DDoS) flooding attacks on TCP-based Web servers. There has been a lot of related work which focuses on analyzing the pattern of the DDoS attacks to protect users from them. However, none of these studies takes all the flags within TCP header into account, nor do they analyze relationship between the flags and the TCP packets. To analyze the features of the DDoS attacks, therefore, this paper presents a network traffic analysis mechanism which computes the ratio of the number of TCP flags to the total number of TCP packets. Based upon the calculation of TCP flag rates, we compile a pair of the TCP flag rates and the presence (or absence) of the DDoS attack into state-action rules using machine learning algorithms. We endow alarming agents with a tapestry of the compiled rules. The agents can then detect network flooding attacks against a Web server. We validate our framework with experimental results in a simulated TCP-based network setting. The experimental results show a distinctive and predictive pattern of the DDoS attacks, and our alarming agents can successfully detect various DDoS attacks.
引用
收藏
页码:286 / 295
页数:10
相关论文
共 50 条
  • [1] Distributed Denial of Service (DDoS) Attacks Detection: A Machine Learning Approach
    Samom, Premson Singh
    Taggu, Amar
    [J]. APPLIED SOFT COMPUTING AND COMMUNICATION NETWORKS, 2021, 187 : 75 - 87
  • [2] Evaluation of Experiments on Detecting Distributed Denial of Service (DDoS) Attacks in Eucalyptus Private Cloud
    Lonea, Alina Madalina
    Popescu, Daniela Elena
    Prostean, Octavian
    Tianfield, Huaglory
    [J]. SOFT COMPUTING APPLICATIONS, 2013, 195 : 367 - 379
  • [3] DISTRIBUTED DENIAL OF SERVICE (DDOS) NETWORK ATTACKS: IMPACT ON THE VIRTUAL LEARNING ENVIRONMENT
    Atayero, A. A.
    Oshin, O. I.
    Oshin, B. O.
    Alatishe, A. S.
    [J]. ICERI2014: 7TH INTERNATIONAL CONFERENCE OF EDUCATION, RESEARCH AND INNOVATION, 2014, : 2235 - 2240
  • [4] Distributed Denial of Service (DDoS) Attacks Detection Using Machine Learning Prototype
    Hoyos Ll, Manuel S.
    Isaza E, Gustavo A.
    Velez, Jairo I.
    Castillo O, Luis
    [J]. DISTRIBUTED COMPUTING AND ARTIFICIAL INTELLIGENCE, (DCAI 2016), 2016, 474 : 33 - 41
  • [5] Detecting Distributed Denial of Service Attacks using Machine Learning Models
    Alghoson, Ebtihal Sameer
    Abbass, Onytra
    [J]. INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2021, 12 (12) : 616 - 622
  • [6] Detecting distributed denial of service attacks by sharing distributed beliefs
    Peng, T
    Leckie, C
    Ramamohanarao, K
    [J]. INFORMATION SECURITY AND PRIVACY, PROCEEDINGS, 2003, 2727 : 214 - 225
  • [7] Protecting against distributed denial of service (DDoS) attacks using distributed filtering
    Trostle, Jonathan
    [J]. 2006 SECURECOMM AND WORKSHOPS, 2006, : 201 - 211
  • [8] Detecting and Reacting against Distributed Denial of Service Attacks
    Bouzida, Yacine
    Cuppens, Frederic
    Gombault, Sylvain
    [J]. 2006 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, VOLS 1-12, 2006, : 2394 - 2399
  • [9] Present Status of Distributed Denial of service (DDoS) Attacks in Internet World
    Singh, Rajeev
    Sharma, T. P.
    [J]. INTERNATIONAL JOURNAL OF MATHEMATICAL ENGINEERING AND MANAGEMENT SCIENCES, 2019, 4 (04) : 1008 - 1017
  • [10] The Distributed Denial of Service Attacks (DDoS) Prevention Mechanisms on Application Layer
    Bhosale, Karuna S.
    Nenova, Maria
    Iliev, Georgi
    [J]. 2017 13TH INTERNATIONAL CONFERENCE ON ADVANCED TECHNOLOGIES, SYSTEMS AND SERVICES IN TELECOMMUNICATIONS (TELSIKS), 2017, : 136 - 139