Generalized Network Temperature for DDoS Detection through Renyi Entropy

被引:1
|
作者
Wang, Xiang [1 ]
Zhang, Xing [1 ]
Wang, Changda [1 ]
机构
[1] Jiangsu Univ, Zhenjiang, Jiangsu, Peoples R China
关键词
network anomaly detection; generalized network temperature; EWMA; SOFTWARE-DEFINED NETWORKING; ATTACKS;
D O I
10.1109/QRS-C57518.2022.00014
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Distributed Denial-of-Services (DDoS) are serious network threats hardly eliminated. Current network entropy-based DDoS detection methods suffer from distinguishing DDoS attack traffic among normal traffic through a fixed empirical detection threshold, i.e., most of such thresholds are case-sensitive ones. With the Renyi entropy of a network, the paper devised a Generalized Network Temperature (GNT) based approach for DDoS attack detection, where GNT is a novel and fine-granular-scale statistical indicator that describes the network entropy changes in the light of both network traffic and network topology changes. Within a series of predefined time windows, our proposed approach first collects the selected network traffic features and then calculates the GNT for each time window. Second, the DDoS attacks are then acknowledged or denied by comparing each GNT to a dynamically adjustable threshold generated by the Exponentially Weighted Moving Average (EWMA) model. Furthermore, the publicly available CIC DoS 2017 dataset is utilized to test the proposed approach in the paper. The experimental results show that our proposed approach outperforms the known Shannon entropy-based DDoS attack detection methods with respect to both efficacy and efficiency.
引用
收藏
页码:24 / 33
页数:10
相关论文
共 50 条
  • [31] DDoS Attack Detection using Fast Entropy Approach on Flow-Based Network Traffic
    David, Jisa
    Thomas, Ciza
    BIG DATA, CLOUD AND COMPUTING CHALLENGES, 2015, 50 : 30 - 36
  • [32] Combining Renyi Entropy and EWMA to Detect Common Attacks in Network
    Yan, Ruoyu
    INTERNATIONAL JOURNAL OF PATTERN RECOGNITION AND ARTIFICIAL INTELLIGENCE, 2016, 30 (10)
  • [33] A new information dimension of complex network based on Renyi entropy
    Duan, Shuyu
    Wen, Tao
    Jiang, Wen
    PHYSICA A-STATISTICAL MECHANICS AND ITS APPLICATIONS, 2019, 516 : 529 - 542
  • [34] Improving DDoS Detection in IoT Networks Through Analysis of Network Traffic Characteristics
    Costa, Wanderson L.
    Silveira, Matheus M.
    de Araujo, Thelmo
    Gomes, Rafael L.
    2020 IEEE LATIN-AMERICAN CONFERENCE ON COMMUNICATIONS (LATINCOM 2020), 2020,
  • [35] Cramer-Rao and moment-entropy inequalities for Renyi entropy and generalized fisher information
    Lutwak, E
    Yang, D
    Zhang, GY
    IEEE TRANSACTIONS ON INFORMATION THEORY, 2005, 51 (02) : 473 - 478
  • [36] Discrete gravity on random tensor network and holographic Renyi entropy
    Han, Muxin
    Huang, Shilin
    JOURNAL OF HIGH ENERGY PHYSICS, 2017, (11):
  • [37] Entropy Methods for DDoS Attacks Detection in Telecommunication Systems
    Popovskyy, Vladimir
    Skibin, Vladislav
    2014 FIRST INTERNATIONAL SCIENTIFIC-PRACTICAL CONFERENCE PROBLEMS OF INFOCOMMUNICATIONS SCIENCE AND TECHNOLOGY (PIC S&T), 2014, : 182 - 185
  • [38] DDoS attack detection algorithms based on entropy computing
    Li, Liying
    Zhou, Jianying
    Xiao, Ning
    INFORMATION AND COMMUNICATIONS SECURITY, PROCEEDINGS, 2007, 4681 : 452 - +
  • [39] Joint Entropy Analysis Model for DDoS Attack Detection
    Rahmani, Hamza
    Sahli, Nabil
    Kammoun, Farouk
    FIFTH INTERNATIONAL CONFERENCE ON INFORMATION ASSURANCE AND SECURITY, VOL 2, PROCEEDINGS, 2009, : 267 - 271
  • [40] DDoS detection in high speed network
    Department of Computer Science and Technology, Nanjing University, Nanjing 210093, China
    不详
    Jisuanji Gongcheng, 2006, 10 (154-156):