Detection of variations of local irregularity of traffic under DDOS flood attack
Summary: The aim of Distributed Denial-Of-Service (DDOS) flood attacks is to overwhelm the attacked site or to make its service performance deterioration considerably by sending flood packets to the target from the machines distributed all over the world. This is a kind of local behavior of traffic at the protected site because the attacked site can be recovered to its normal service state sooner or later even though it is in reality overwhelmed during attack. From a view of mathematics, it can be taken as a kind of short-range phenomenon in computer networks. In this paper, we use the Hurst parameter (H) to measure the local irregularity or self-similarity of traffic under DDOS flood attack provided that fractional Gaussian noise (fGn) is used as the traffic model. As flood attack packets of DDOS make the H value of arrival traffic vary significantly away from that of traffic normally arriving at the protected site, we discuss a method to statistically detect signs of DDOS flood attacks with predetermined detection probability and false alarm probability.
- Note on studying change point of LRD traffic based on Li's detection of DDoS flood attacking
- A model to partly but reliably distinguish DDOS flood traffic from aggregated one
- Dynamic modeling of internet traffic for intrusion detection
- Detecting distributed denial of service attack based on multi-feature fusion
- DDoS Attack Detection Algorithm Using IP Address Features
- scientific article; zbMATH DE number 3860431 (Why is no real title available?)
- scientific article; zbMATH DE number 1233828 (Why is no real title available?)
- scientific article; zbMATH DE number 1520578 (Why is no real title available?)
- scientific article; zbMATH DE number 839561 (Why is no real title available?)
- scientific article; zbMATH DE number 847242 (Why is no real title available?)
- scientific article; zbMATH DE number 1404558 (Why is no real title available?)
- scientific article; zbMATH DE number 1418969 (Why is no real title available?)
- Modeling autocorrelation functions of self-similar teletraffic in communication networks based on optimal approximation in Hilbert space
- Self-similar processes in communications networks
- On von Kármán spectrum from a view of fractal
- A model to partly but reliably distinguish DDOS flood traffic from aggregated one
- Reconstructing the parameter for massive abnormal TCP connection with Bloom filter
- Information Security and Cryptology
- A class of negatively fractal dimensional Gaussian random functions
- Asymptotic identity in min-plus algebra: a report on CPNS
- Dynamic modeling of internet traffic for intrusion detection
- Fractal time series -- A tutorial review
- Variance bound of ACF estimation of one block of fGn with LRD
- Building representative-based data aggregation tree in wireless sensor networks
- Detecting pulsing denial-of-service attacks with nondeterministic attack intervals
- Note on studying change point of LRD traffic based on Li's detection of DDoS flood attacking
This page was built for publication: Detection of variations of local irregularity of traffic under DDOS flood attack
Report a bug (only for logged in users!)Click here to report a bug for this page (MaRDI item Q1023231)