跳到主要导航 跳到搜索 跳到主要内容

A new way to detect DDoS attacks within single router

  • Xi'an Jiaotong University
  • Guangdong Ocean University

科研成果: 会议稿件论文同行评审

5 引用 (Scopus)

摘要

Different from other research work focusing on network-wide traffic, the traffic we focus on for analysis is that of a traffic state viewed from a router's interior. In this paper, at first, a kind of Port-to-Port traffic in a router is introduced, which we call IF flow. IF flows can amplify the ratio of attack traffic to normal traffic. Then RLS (recursive least square) filter is used to predict IF flows. After that, a statistical method using residual filtered process is proposed to detect anomalies. Finally we respectively apply the method to three types of traffics: IF flows, input links and output links within a router, and compare the anomaly detection results using ROC curves. Results show that IF flows are more powerful than input links and output links in DDoS attacks detection.

源语言英语
1192-1196
页数5
DOI
出版状态已出版 - 2008
活动2008 11th IEEE Singapore International Conference on Communication Systems, ICCS 2008 - Guangzhou, 中国
期限: 19 11月 200821 11月 2008

会议

会议2008 11th IEEE Singapore International Conference on Communication Systems, ICCS 2008
国家/地区中国
Guangzhou
时期19/11/0821/11/08

学术指纹

探究 'A new way to detect DDoS attacks within single router' 的科研主题。它们共同构成独一无二的学术指纹。

引用此