DDoS Attacks Detection and Traceback Method Based on Flow Entropy Algorithm and MPLS Principle

被引:1
|
作者
Yang, Xiaohui [1 ]
Yu, Yue [1 ]
机构
[1] Hebei Univ, Baoding 071002, Peoples R China
来源
CLOUD COMPUTING AND SECURITY, PT II | 2018年 / 11064卷
基金
国家重点研发计划;
关键词
Cloud computing security; DDoS attacks; Single packet traceback technology; Flow entropy algorithm; Attack flow recognition; IP; DOS;
D O I
10.1007/978-3-030-00009-7_60
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Distributed Denial of Service (DDoS) attacks on cloud computing platforms have become one of the key issues affecting cloud security. Single packet traceback technology against DDoS attacks has become the focus of research in the field of cloud security. Currently, single packet traceback technologies generally have problems of high cost and low accuracy. In this paper, an early warning mechanism is set up, the broadcast algorithm is improved, to avoid detecting the router is flooded with a large amount of redundant broadcast message, and the flow entropy is used to recognize the attack flow. A traceback method for the switching path generation theory based on MPLS (Multi-Protocol Label Switching) that establishing traceback marks on the traceable routers and reconstructing the DDoS attacks paths is proposed. This paper uses network probe to parallelize the establishment of traceback tables and estimate the load of traceback devices and so on to improve the processing speed and traceback accuracy of traceback routers. The simulation results show that the flow entropy method can recognize DDoS attacks when the strength of attack flow is nearly 2 times normal flow, and the probability of traceback can be reduced to 6%. After the establishment of traceback paths, the forwarding rate and traceback rate of IP packets are improved, the traceback accuracy than other methods to improve 30%, suitable for cloud computing large scale and high flow environment.
引用
收藏
页码:670 / 683
页数:14
相关论文
共 50 条
  • [1] Traceback of DDoS Attacks Using Entropy Variations
    Yu, Shui
    Zhou, Wanlei
    Doss, Robin
    Jia, Weijia
    IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2011, 22 (03) : 412 - 425
  • [2] A Collaborative Detection and IP Traceback Algorithm for Low-rate DDos Attacks
    Gui, Bingxiang
    Zhou, Wanlei
    Zhou, Kang
    4TH INTERNATIONAL CONFERENCE ON MATERIALS ENGINEERING FOR ADVANCED TECHNOLOGIES (ICMEAT 2015), 2015, : 546 - 549
  • [3] A DDoS attacks traceback scheme for SDN-based smart city
    Chen, Wen
    Xiao, Suchao
    Liu, Leijie
    Jiang, Xueqin
    Tang, Zhangbin
    COMPUTERS & ELECTRICAL ENGINEERING, 2020, 81
  • [4] A Method Based on AMHI for DDoS Attacks Detection and Defense
    Bu, Kai
    Sun, Zhixin
    PROCEEDINGS OF THE 9TH INTERNATIONAL CONFERENCE FOR YOUNG COMPUTER SCIENTISTS, VOLS 1-5, 2008, : 1571 - 1576
  • [5] Cooperative Detection Method for DDoS Attacks Based on Blockchain
    Cheng, Jieren
    Yao, Xinzhi
    Li, Hui
    Lu, Hao
    Xiong, Naixue
    Luo, Ping
    Liu, Le
    Guo, Hao
    Feng, Wen
    COMPUTER SYSTEMS SCIENCE AND ENGINEERING, 2022, 43 (01): : 103 - 117
  • [6] Entropy-Based Collaborative Detection of DDOS Attacks on Community Networks
    Yu, Shui
    Zhou, Wanlei
    2008 IEEE INTERNATIONAL CONFERENCE ON PERVASIVE COMPUTING AND COMMUNICATIONS, 2008, : 566 - 571
  • [7] Entropy Based Detection of DDoS Attacks in Packet Switching Network Models
    Lawniczak, Anna T.
    Wu, Hao
    Di Stefano, Bruno
    COMPLEX SCIENCES, PT 2, 2009, 5 : 1810 - +
  • [8] TDFA: Traceback-based Defense against DDoS Flooding Attacks
    Foroushani, Vahid Aghaei
    Zincir-Heywood, A. Nur
    2014 IEEE 28TH INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS (AINA), 2014, : 597 - 604
  • [9] Evaluation of Flow and Average Entropy Based Detection Mechanism for DDoS Attacks using NS-2
    Vadehra, Raghav
    Singh, Manjit
    Singh, Butta
    Chowdhary, Nitika
    INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2016, 10 (05): : 139 - 145
  • [10] DDoS Detection Method Based on Improved Generalized Entropy
    Li, Jiaqi
    Yang, Xu
    Chen, Hui
    Lin, Haoqiang
    Chen, Xinqing
    Liu, Yanhua
    ADVANCES IN NATURAL COMPUTATION, FUZZY SYSTEMS AND KNOWLEDGE DISCOVERY, ICNC-FSKD 2022, 2023, 153 : 519 - 526