Low-Rate DDoS Attack Detection Using Expectation of Packet Size

被引:32
|
作者
Zhou, Lu [1 ]
Liao, Mingchao [1 ]
Yuan, Cao [1 ]
Zhang, Haoyu [1 ]
机构
[1] Wuhan Polytech Univ, Sch Math & Comp Sci, Wuhan 430023, Hubei, Peoples R China
基金
中国国家自然科学基金;
关键词
D O I
10.1155/2017/3691629
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Low-rate Distributed Denial-of-Service (low-rate DDoS) attacks are a new challenge to cyberspace, as the attackers send a large amount of attack packets similar to normal traffic, to throttle legitimate flows. In this paper, we propose a measurement-expectation of packet size-that is based on the distribution difference of the packet size to distinguish two typical low-rate DDoS attacks, the constant attack and the pulsing attack, from legitimate traffic. The experimental results, obtained using a series of real datasets with different times and different tolerance factors, are presented to demonstrate the effectiveness of the proposed measurement. In addition, extensive experiments are performed to show that the proposed measurement can detect the low-rate DDoS attacks not only in the short and long terms but also for low packet rates and high packet rates. Furthermore, the false-negative rates and the adjudication distance can be adjusted based on the detection sensitivity requirements.
引用
收藏
页数:14
相关论文
共 50 条
  • [41] A novel multi-scale CNN and Bi-LSTM arbitration dense network model for low-rate DDoS attack detection
    Yin, Xiaochun
    Fang, Wei
    Liu, Zengguang
    Liu, Deyong
    SCIENTIFIC REPORTS, 2024, 14 (01)
  • [42] Low-rate DoS Attack Detection Based on WPD-EE Algorithm
    Wang, Xiaocai
    Yang, Qiuwei
    Xie, Zichao
    Zheng, Zhiqing
    Yan, Yudong
    Tang, Dan
    2020 IEEE INTL SYMP ON PARALLEL & DISTRIBUTED PROCESSING WITH APPLICATIONS, INTL CONF ON BIG DATA & CLOUD COMPUTING, INTL SYMP SOCIAL COMPUTING & NETWORKING, INTL CONF ON SUSTAINABLE COMPUTING & COMMUNICATIONS (ISPA/BDCLOUD/SOCIALCOM/SUSTAINCOM 2020), 2020, : 384 - 391
  • [43] An effective DDoS attack detection and packet-filtering scheme
    Jeong, Seokbong
    Kim, Hyunwoo
    Kim, Sehun
    IEICE TRANSACTIONS ON COMMUNICATIONS, 2006, E89B (07) : 2033 - 2042
  • [44] A Low-rate DoS Attack Detection Method Based on Hilbert Spectrum and Correlation
    Tang, Dan
    Wu, Xiaoxue
    Tang, Liu
    Man, Jianping
    Zhan, Sijia
    Liu, Qin
    2018 IEEE SMARTWORLD, UBIQUITOUS INTELLIGENCE & COMPUTING, ADVANCED & TRUSTED COMPUTING, SCALABLE COMPUTING & COMMUNICATIONS, CLOUD & BIG DATA COMPUTING, INTERNET OF PEOPLE AND SMART CITY INNOVATION (SMARTWORLD/SCALCOM/UIC/ATC/CBDCOM/IOP/SCI), 2018, : 1358 - 1363
  • [45] The use of statistical features for low-rate denial-of-service attack detection
    Fuladi, Ramin
    Baykas, Tuncer
    Anarim, Emin
    ANNALS OF TELECOMMUNICATIONS, 2024, 79 (9-10) : 679 - 691
  • [46] A Low-rate DDoS Strategy for Unknown Bottleneck Link Characteristics
    Takahashi, Yuta
    Inamura, Hiroshi
    Nakamura, Yoshitaka
    2021 IEEE INTERNATIONAL CONFERENCE ON PERVASIVE COMPUTING AND COMMUNICATIONS WORKSHOPS AND OTHER AFFILIATED EVENTS (PERCOM WORKSHOPS), 2021, : 508 - 513
  • [47] Packet_In message based DDoS attack detection in SDN network using OpenFlow
    You, Xiang
    Feng, Yaokai
    Sakurai, Kouichi
    2017 FIFTH INTERNATIONAL SYMPOSIUM ON COMPUTING AND NETWORKING (CANDAR), 2017, : 522 - 528
  • [48] LtRFT: Mitigate the Low-Rate Data Plane DDoS Attack With Learning-To-Rank Enabled Flow Tables
    Tang, Dan
    Yan, Yudong
    Gao, Chenjun
    Liang, Wei
    Jin, Wenqiang
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2023, 18 : 3143 - 3157
  • [49] Attack simulation and signature extraction of low-rate DoS
    Liu, Zenghui
    Guan, Liguo
    2010 THIRD INTERNATIONAL SYMPOSIUM ON INTELLIGENT INFORMATION TECHNOLOGY AND SECURITY INFORMATICS (IITSI 2010), 2010, : 544 - 548
  • [50] Improved RED Algorithm for Low-Rate DoS Attack
    Ma, Li
    Chen, Jie
    Zhang, Bo
    ADVANCES IN ELECTRONIC COMMERCE, WEB APPLICATION AND COMMUNICATION, VOL 1, 2012, 148 : 311 - 316