Discriminating DDoS Flows from Flash Crowds Using Information Distance

被引:0
|
作者
Yu, Shui [1 ]
Thapngam, Theerasak [1 ]
Liu, Jianwen [1 ]
Wei, Su [1 ]
Zhou, Wanlei [1 ]
机构
[1] Deakin Univ, Burwood, Vic 3125, Australia
关键词
DDoS Attack; Distance; Measurement; ATTACKS;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Discriminating DDoS flooding attacks from flash crowds poses a tough challenge for the network security community. Because of the vulnerability of the original design of the Internet, attackers can easily mimic the patterns of legitimate network traffic to fly under the radar. The existing fingerprint or feature based algorithms are incapable to detect new attack strategies. In this paper, we aim to differentiate DDoS attack flows from flash crowds. We are motivated by the following fact: the attack flows are generated by the same pre-built program (attack tools), however, flash crowds come from randomly distributed users all over the Internet. Therefore, the flow similarity among DDoS attack flows is much stronger than that among flash crowds. We employ abstract distance metrics, the Jeffrey distance, the Sibson distance, and the Hellinger distance to measure the similarity among flows to achieve our goal. We compared the three metrics and found that the Sibson distance is the most suitable one for our purpose. We apply our algorithm to the real datasets and the results indicate that the proposed algorithm can differentiate them with an accuracy around 65%.
引用
收藏
页码:351 / 356
页数:6
相关论文
共 50 条
  • [1] Discriminating DDoS Attacks from Flash Crowds Using Flow Correlation Coefficient
    Yu, Shui
    Zhou, Wanlei
    Jia, Weijia
    Guo, Song
    Xiang, Yong
    Tang, Feilong
    [J]. IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2012, 23 (06) : 1073 - 1080
  • [2] Discriminating flash crowds from DDoS attacks using efficient thresholding algorithm
    David, Jisa
    Thomas, Ciza
    [J]. JOURNAL OF PARALLEL AND DISTRIBUTED COMPUTING, 2021, 152 : 79 - 87
  • [3] Detection of spoofed and non-spoofed DDoS attacks and discriminating them from flash crowds
    Gera J.
    Battula B.P.
    [J]. Eurasip Journal on Information Security, 2018, 2018 (01)
  • [4] Distinguishing DDoS Attacks from Flash Crowds Using Probability Metrics
    Li, Ke
    Zhou, Wanlei
    Li, Ping
    Hai, Jing
    Liu, Jianwen
    [J]. NSS: 2009 3RD INTERNATIONAL CONFERENCE ON NETWORK AND SYSTEM SECURITY, 2009, : 9 - 17
  • [5] An information divergence based approach to detect flooding DDoS attacks and Flash Crowds
    Kaur, Gursharanjeet
    Behal, Sunny
    Shifali
    [J]. PROCEEDINGS OF THE 2017 3RD INTERNATIONAL CONFERENCE ON APPLIED AND THEORETICAL COMPUTING AND COMMUNICATION TECHNOLOGY (ICATCCT), 2017, : 251 - 258
  • [6] A Survey of Discriminating Distributed DoS Attacks from Flash Crowds
    Rao, N. Srihari
    Sekharaiah, K. Chandra
    Rao, A. Ananda
    [J]. SMART TRENDS IN INFORMATION TECHNOLOGY AND COMPUTER COMMUNICATIONS, SMARTCOM 2016, 2016, 628 : 733 - 742
  • [7] A Multimetric Approach for Discriminating Distributed Denial of Service Attacks from Flash Crowds
    Elhadef, Mourad
    [J]. ADVANCED MULTIMEDIA AND UBIQUITOUS ENGINEERING: FUTURE INFORMATION TECHNOLOGY, VOL 2, 2016, 354 : 17 - 23
  • [8] AN EFFECTIVE METHOD FOR DIFFERENTIATING BETWEEN DDOS ATTACKS AND FLASH CROWDS
    Yan, Ruoyu
    Wang, Yingfeng
    [J]. INTERNATIONAL JOURNAL OF INNOVATIVE COMPUTING INFORMATION AND CONTROL, 2024, 20 (01): : 31 - 46
  • [9] Improving Discriminating Accuracy Rate of DDoS Attacks and Flash Events
    Agha, Sahareesh
    Rehman, Osama
    Rahman, Ibrahim M. H.
    [J]. INTERNATIONAL JOURNAL OF CYBER WARFARE AND TERRORISM, 2021, 11 (04) : 21 - 42
  • [10] A Behavior-Based Method for Distinction of Flooding DDoS and Flash Crowds
    Sun, Degang
    Yang, Kun
    Shi, Zhixin
    Lv, Bin
    [J]. KNOWLEDGE SCIENCE, ENGINEERING AND MANAGEMENT (KSEM 2017): 10TH INTERNATIONAL CONFERENCE, KSEM 2017, MELBOURNE, VIC, AUSTRALIA, AUGUST 19-20, 2017, PROCEEDINGS, 2017, 10412 : 129 - 136