A Low-rate DoS Detection Based on Rate Anomalies

被引:0
|
作者
Wu, Libing [1 ]
Cheng, Jing [1 ]
He, Yanxiang [1 ]
Xu, Ao [1 ]
Wen, Peng [2 ]
机构
[1] Wuhan Univ, Sch Comp, Wuhan, Peoples R China
[2] Wuhan Univ, Sch Informat Management, Wuhan, Peoples R China
基金
中国国家自然科学基金; 美国国家科学基金会;
关键词
Network Security; Congestion Control; Denial of Service; Low-Rate attack;
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Low-rate Denial-of-Service attacks are stealthier and trickier than traditional DDoS attacks. According to the characteristic of periodicity and short burst in LDoS flows, a detection measure against LDoS attacks based on rate anomalies has been proposed. In the period when the router packet loss-rate is abnormal caused by the attack pulse, the rate of attack flow is large, while in other time the rate of attack flow is close to 0. In the view point of the periods that the packet loss is abnormal, we can find that the attack flow rate is far higher in these periods than the average rate, while the normal flow is lower to the average rate. In this paper, we proposed a measure that observes the flow rate in the periods that the packet loss rate is abnormal, computing the difference of the rate in these periods and the average rate. If it is beyond a certain threshold, treats the flow as a malicious flow and filters the flow with corresponding method.
引用
收藏
页码:89 / 92
页数:4
相关论文
共 50 条
  • [31] AccFlow: Defending against the Low-Rate TCP DoS Attack in Drones
    Cao, Yuan
    Li, Haotian
    Han, Lijuan
    Zhao, Xiaojin
    Pan, Xiaofang
    Yao, Enyi
    [J]. APPLIED SCIENCES-BASEL, 2023, 13 (21):
  • [32] Assessment of a vulnerability in iterative servers enabling low-rate DoS attacks
    Macia-Fernandez, Gabriel
    Diaz-Verdejo, Jesus E.
    Garcia-Teodoro, Pedro
    [J]. COMPUTER SECURITY - ESORICS 2006, PROCEEDINGS, 2006, 4189 : 512 - +
  • [33] A Queuing Analysis for Low-rate DoS Attacks against Application Servers
    Xu, Xiaodong
    Guo, Xiao
    Zhu, Shirui
    [J]. 2010 IEEE INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS, NETWORKING AND INFORMATION SECURITY (WCNIS), VOL 1, 2010, : 500 - 504
  • [34] Mathematical Model for Low-Rate DoS Attacks Against Application Servers
    Macia-Fernandez, Gabriel
    Diaz-Verdejo, Jesus
    Garcia-Teodoro, Pedro
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2009, 4 (03) : 519 - 529
  • [35] Analysis of low-rate TCP DoS attack against FAST TCP
    Dong, Kuo
    Yang, Shoubao
    Wang, Shaolin
    [J]. ISDA 2006: SIXTH INTERNATIONAL CONFERENCE ON INTELLIGENT SYSTEMS DESIGN AND APPLICATIONS, VOL 3, 2006, : 86 - +
  • [36] Modeling the Vulnerability of Feedback-Control Based Internet Services to Low-Rate DoS Attacks
    Tang, Yajuan
    Luo, Xiapu
    Hui, Qing
    Chang, Rocky K. C.
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2014, 9 (03) : 339 - 353
  • [37] LOW-RATE SMOKERS
    OWEN, N
    KENT, P
    WAKEFIELD, M
    ROBERTS, L
    [J]. PREVENTIVE MEDICINE, 1995, 24 (01) : 80 - 84
  • [38] A Behavior-based Detection Method for Outbreaks of Low-rate Attacks
    Feng, Yaokai
    Hori, Yoshiaki
    Sakurai, Kouichi
    Takeuchi, Jun'ichi
    [J]. 2012 IEEE/IPSJ 12TH INTERNATIONAL SYMPOSIUM ON APPLICATIONS AND THE INTERNET (SAINT), 2012, : 267 - 272
  • [39] Detectability of Low-Rate HTTP Server DoS Attacks using Spectral Analysis
    Brynielsson, Joel
    Sharma, Rishie
    [J]. PROCEEDINGS OF THE 2015 IEEE/ACM INTERNATIONAL CONFERENCE ON ADVANCES IN SOCIAL NETWORKS ANALYSIS AND MINING (ASONAM 2015), 2015, : 954 - 961
  • [40] A FeedForward-Convolutional Neural Network to Detect Low-Rate DoS in IoT
    Ilango, Harun Surej
    Ma, Maode
    Su, Rong
    [J]. ENGINEERING APPLICATIONS OF ARTIFICIAL INTELLIGENCE, 2022, 114