Note on studying change point of LRD traffic based on Li's detection of DDoS flood attacking (Q980674): Difference between revisions
From MaRDI portal
Set OpenAlex properties. |
Created claim: Wikidata QID (P12): Q58653441, #quickstatements; #temporary_batch_1711565664090 |
||
Property / Wikidata QID | |||
Property / Wikidata QID: Q58653441 / rank | |||
Normal rank |
Revision as of 21:17, 27 March 2024
scientific article
Language | Label | Description | Also known as |
---|---|---|---|
English | Note on studying change point of LRD traffic based on Li's detection of DDoS flood attacking |
scientific article |
Statements
Note on studying change point of LRD traffic based on Li's detection of DDoS flood attacking (English)
0 references
29 June 2010
0 references
Summary: Distributed denial-of-service (DDoS) flood attacks remain great threats to the Internet. To ensure network usability and reliability, accurate detection of these attacks is critical. Based on Li's work on DDoS flood attack detection, we propose a DDoS detection method by monitoring the Hurst variation of long-range dependant traffic. Specifically, we use an autoregressive system to estimate the Hurst parameter of normal traffic. If the actual Hurst parameter varies significantly from the estimation, we assume that DDoS attack happens. Meanwhile, we propose two methods to determine the change point of Hurst parameter that indicates the occurrence of DDoS attacks. The detection rate associated with one method and false alarm rate for the other method are also derived. The test results on DARPA intrusion detection evaluation data show that the proposed approaches can achieve better detection performance than some well-known self-similarity-based detection methods.
0 references