Generalized Network Temperature for DDoS Detection through Renyi Entropy

被引:1
|
作者
Wang, Xiang [1 ]
Zhang, Xing [1 ]
Wang, Changda [1 ]
机构
[1] Jiangsu Univ, Zhenjiang, Jiangsu, Peoples R China
关键词
network anomaly detection; generalized network temperature; EWMA; SOFTWARE-DEFINED NETWORKING; ATTACKS;
D O I
10.1109/QRS-C57518.2022.00014
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Distributed Denial-of-Services (DDoS) are serious network threats hardly eliminated. Current network entropy-based DDoS detection methods suffer from distinguishing DDoS attack traffic among normal traffic through a fixed empirical detection threshold, i.e., most of such thresholds are case-sensitive ones. With the Renyi entropy of a network, the paper devised a Generalized Network Temperature (GNT) based approach for DDoS attack detection, where GNT is a novel and fine-granular-scale statistical indicator that describes the network entropy changes in the light of both network traffic and network topology changes. Within a series of predefined time windows, our proposed approach first collects the selected network traffic features and then calculates the GNT for each time window. Second, the DDoS attacks are then acknowledged or denied by comparing each GNT to a dynamically adjustable threshold generated by the Exponentially Weighted Moving Average (EWMA) model. Furthermore, the publicly available CIC DoS 2017 dataset is utilized to test the proposed approach in the paper. The experimental results show that our proposed approach outperforms the known Shannon entropy-based DDoS attack detection methods with respect to both efficacy and efficiency.
引用
收藏
页码:24 / 33
页数:10
相关论文
共 50 条
  • [1] DDoS Detection Method Based on Improved Generalized Entropy
    Li, Jiaqi
    Yang, Xu
    Chen, Hui
    Lin, Haoqiang
    Chen, Xinqing
    Liu, Yanhua
    ADVANCES IN NATURAL COMPUTATION, FUZZY SYSTEMS AND KNOWLEDGE DISCOVERY, ICNC-FSKD 2022, 2023, 153 : 519 - 526
  • [2] Holographic Renyi entropy and generalized entropy method
    Guo, Wu-zhong
    Li, Miao
    NUCLEAR PHYSICS B, 2014, 882 : 128 - 144
  • [3] Effective DDoS Attacks Detection Using Generalized Entropy Metric
    Li, Ke
    Zhou, Wanlei
    Yu, Shui
    Dai, Bo
    ALGORITHMS AND ARCHITECTURES FOR PARALLEL PROCESSING, PROCEEDINGS, 2009, 5574 : 266 - +
  • [4] A low-rate DDoS detection and mitigation for SDN using Renyi Entropy with Packet Drop
    Ahalawat, Anchal
    Babu, Korra Sathya
    Turuk, Ashok Kumar
    Patel, Sanjeev
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2022, 68
  • [5] The generalized Renyi image entropy as a noise indicator
    Gabarda, S.
    Cristobal, G.
    NOISE AND FLUCTUATIONS IN PHOTONICS, QUANTUM OPTICS, AND COMMUNICATIONS, 2007, 6603
  • [6] A generalized complexity measure based on Renyi entropy
    Sanchez-Moreno, Pablo
    Carlos Angulo, Juan
    Dehesa, Jesus S.
    EUROPEAN PHYSICAL JOURNAL D, 2014, 68 (08):
  • [7] DDoS Detection Method Based on Chaos Analysis of Network Traffic Entropy
    Ma, Xinlei
    Chen, Yonghong
    IEEE COMMUNICATIONS LETTERS, 2014, 18 (01) : 114 - 117
  • [8] Entropy Based Detection of DDoS Attacks in Packet Switching Network Models
    Lawniczak, Anna T.
    Wu, Hao
    Di Stefano, Bruno
    COMPLEX SCIENCES, PT 2, 2009, 5 : 1810 - +
  • [9] Renyi entropy-driven network traffic anomaly detection with dynamic threshold
    Yu, Haoran
    Yang, Wenchuan
    Cui, Baojiang
    Sui, Runqi
    Wu, Xuedong
    Cybersecurity, 2024, 7 (01)
  • [10] Computational Detection of Transcription Factor Binding Sites Through Differential Renyi Entropy
    Maynou, Joan
    Gallardo-Chacon, Joan-Josep
    Vallverdu, Montserrat
    Caminal, Pere
    Perera, Alexandre
    IEEE TRANSACTIONS ON INFORMATION THEORY, 2010, 56 (02) : 734 - 741