Detecting distributed denial-of-service attacks using Kolmogorov complexity metrics

被引:33
|
作者
Kulkarni, Amit
Bush, Stephen [1 ]
机构
[1] Rensselaer Polytech Inst, New York, NY USA
[2] Gen Elect Global Res Ctr, Niskayuna, NY USA
关键词
Kolmogorov complexity; denial-of-service attack; active network; entropy; complexity probes;
D O I
10.1007/s10922-005-9016-3
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This paper describes an approach to detecting distributed denial of service (DDoS) attacks that is based on fundamentals of Information Theory, specifically Kolmogorov Complexity. A theorem derived using principles of Kolmogorov Complexity states that the joint complexity measure of random strings is lower than the sum of the complexities of the individual strings when the strings exhibit some correlation. Furthermore, the joint complexity measure varies inversely with the amount of correlation. We propose a distributed active network-based algorithm that exploits this property to correlate arbitrary traffic flows in the network to detect possible denial-of-service attacks. One of the strengths of this algorithm is that it does not require special filtering rules and hence it can be used to detect any type of DDoS attack. We implement and investigate the performance of the algorithm in an active network. Our results show that DDoS attacks can be detected in a manner that is not sensitive to legitimate background traffic.
引用
收藏
页码:69 / 80
页数:12
相关论文
共 50 条
  • [21] Detection of Denial-of-service Attacks
    Anh Quang Tran
    计算机工程, 2002, (S1) : 86 - 91
  • [22] A Coordinated Detection and Response Scheme for Distributed Denial-of-Service Attacks
    Lam, Ho-Yu
    Li, Chi-Pan
    Chanson, Samuel T.
    Yeung, Dit-Yan
    2006 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, VOLS 1-12, 2006, : 2165 - 2170
  • [23] Denial-of-Service Attacks to UMTS
    Bertino, Elisa
    COMPUTER, 2015, 48 (02) : 6 - 6
  • [24] Denial-of-Service Attacks on LoRaWAN
    van Es, Eef
    Vranken, Harald
    Hommersom, Arjen
    13TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY (ARES 2018), 2019,
  • [25] Protecting the Internet from distributed denial-of-service attacks: A proposal
    Crocker, SD
    PROCEEDINGS OF THE IEEE, 2004, 92 (09) : 1375 - 1381
  • [26] Analysis of the effects of distributed denial-of-service attacks on MPLS networks
    Genge, Bela
    Siaterlis, Christos
    INTERNATIONAL JOURNAL OF CRITICAL INFRASTRUCTURE PROTECTION, 2013, 6 (02) : 87 - 95
  • [27] Distributed denial-of-service attacks against HTTP/2 services
    Adi, Erwin
    Baig, Zubair A.
    Hingston, Philip
    Lam, Chiou-Peng
    CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2016, 19 (01): : 79 - 86
  • [28] Distributed denial-of-service attacks against HTTP/2 services
    Erwin Adi
    Zubair A. Baig
    Philip Hingston
    Chiou-Peng Lam
    Cluster Computing, 2016, 19 : 79 - 86
  • [29] Detecting distributed denial of service attacks by sharing distributed beliefs
    Peng, T
    Leckie, C
    Ramamohanarao, K
    INFORMATION SECURITY AND PRIVACY, PROCEEDINGS, 2003, 2727 : 214 - 225
  • [30] On detecting distributed denial of service attacks using fuzzy inference system
    Almseidin, Mohammad
    Al-Sawwa, Jamil
    Alkasassbeh, Mouhammd
    Alweshah, Mohammed
    CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2023, 26 (02): : 1337 - 1351