Generalized Network Temperature for DDoS Detection through Renyi Entropy

被引:1
|
作者
Wang, Xiang [1 ]
Zhang, Xing [1 ]
Wang, Changda [1 ]
机构
[1] Jiangsu Univ, Zhenjiang, Jiangsu, Peoples R China
关键词
network anomaly detection; generalized network temperature; EWMA; SOFTWARE-DEFINED NETWORKING; ATTACKS;
D O I
10.1109/QRS-C57518.2022.00014
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Distributed Denial-of-Services (DDoS) are serious network threats hardly eliminated. Current network entropy-based DDoS detection methods suffer from distinguishing DDoS attack traffic among normal traffic through a fixed empirical detection threshold, i.e., most of such thresholds are case-sensitive ones. With the Renyi entropy of a network, the paper devised a Generalized Network Temperature (GNT) based approach for DDoS attack detection, where GNT is a novel and fine-granular-scale statistical indicator that describes the network entropy changes in the light of both network traffic and network topology changes. Within a series of predefined time windows, our proposed approach first collects the selected network traffic features and then calculates the GNT for each time window. Second, the DDoS attacks are then acknowledged or denied by comparing each GNT to a dynamically adjustable threshold generated by the Exponentially Weighted Moving Average (EWMA) model. Furthermore, the publicly available CIC DoS 2017 dataset is utilized to test the proposed approach in the paper. The experimental results show that our proposed approach outperforms the known Shannon entropy-based DDoS attack detection methods with respect to both efficacy and efficiency.
引用
收藏
页码:24 / 33
页数:10
相关论文
共 50 条
  • [41] Early detection of DDoS based on φ-entropy in SDN networks
    Li, Runyu
    Wu, Bin
    PROCEEDINGS OF 2020 IEEE 4TH INFORMATION TECHNOLOGY, NETWORKING, ELECTRONIC AND AUTOMATION CONTROL CONFERENCE (ITNEC 2020), 2020, : 731 - 735
  • [42] Entropy based DDoS Detection in Software Defined Networks
    Fioravanti, Giovanni
    Spina, Mattia Giovanni
    De Rango, Floriano
    2023 IEEE 20TH CONSUMER COMMUNICATIONS & NETWORKING CONFERENCE, CCNC, 2023,
  • [43] Cusum - Entropy: An efficient method for DDoS attack detection
    Ozcelik, Ilker
    Brooks, Richard R.
    2016 4TH INTERNATIONAL ISTANBUL SMART GRID CONGRESS AND FAIR (ICSG), 2016, : 85 - 89
  • [44] An Application of Renyi Entropy Segmentation In Fault Detection of Rotating Machinery
    Popescu, Theodor D.
    Dumitrascu, Bogdan
    2015 16TH INTERNATIONAL CONFERENCE ON RESEARCH AND EDUCATION IN MECHATRONICS (REM), 2015, : 288 - 295
  • [45] Holographic calculation for large interval Renyi entropy at high temperature
    Chen, Bin
    Wu, Jie-qiang
    PHYSICAL REVIEW D, 2015, 92 (10):
  • [46] Detect and Identify DDoS Attacks from Flash Crowd Based on Self-similarity and Renyi Entropy
    Yan, Ruoyu
    Xu, Guoyu
    Qin, XueJing
    2017 CHINESE AUTOMATION CONGRESS (CAC), 2017, : 7188 - 7194
  • [47] Experimental Detection of the Correlation Renyi Entropy in the Central Spin Model
    Niknam, Mohamad
    Santos, Lea F.
    Cory, David G.
    PHYSICAL REVIEW LETTERS, 2021, 127 (08)
  • [48] Multi-scale Entropy and Renyi Cross Entropy Based Traffic Anomaly Detection
    Yan, Ruoyu
    Zheng, Qinghua
    Peng, Weimin
    2008 11TH IEEE SINGAPORE INTERNATIONAL CONFERENCE ON COMMUNICATION SYSTEMS (ICCS), VOLS 1-3, 2008, : 554 - +
  • [49] Detection of transcription factor binding sites using Renyi entropy
    Maynou, Joan
    Vallverdu, Montserrat
    Claria, Francesc
    Perera, Alexandre
    Caminal, Pere
    8TH IEEE INTERNATIONAL CONFERENCE ON BIOINFORMATICS AND BIOENGINEERING, VOLS 1 AND 2, 2008, : 601 - +
  • [50] Detection of multipartite correlation transfer via discrete Renyi entropy
    Munoz, Carlos
    Roa, Luis
    Klimov, Andrei B.
    PHYSICAL REVIEW A, 2024, 109 (01)