跳到主要导航 跳到搜索 跳到主要内容

Combining adaptive filtering and IF flows to detect DDOS attacks within a router

  • Xi'an Jiaotong University
  • Guangdong Ocean University
  • Union University

科研成果: 期刊稿件文章同行评审

7 引用 (Scopus)

摘要

Traffic matrix-based anomaly detection and DDoS attacks detection in networks are research focus in the network security and traffic measurement community. In this paper, firstly, a new type of unidirectional flow called IF flow is proposed. Merits and features of IF flows are analyzed in detail and then two efficient methods are introduced in our DDoS attacks detection and evaluation scheme. The first method uses residual variance ratio to detect DDoS attacks after Recursive Least Square (RLS) filter is applied to predict IF flows. The second method uses generalized likelihood ratio (GLR) statistical test to detect DDoS attacks after a Kalman filter is applied to estimate IF flows. Based on the two complementary methods, an evaluation formula is proposed to assess the seriousness of current DDoS attacks on router ports. Furthermore, the sensitivity of three types of traffic (IF flow, input link and output link) to DDoS attacks is analyzed and compared. Experiments show that IF flow has more power to expose anomaly than the other two types of traffic. Finally, two proposed methods are compared in terms of detection rate, processing speed, etc., and also compared in detail with Principal Component Analysis (PCA) and Cumulative Sum (CUSUM) methods. The results demonstrate that adaptive filter methods have higher detection rate, lower false alarm rate and smaller detection lag time,

源语言英语
页(从-至)428-451
页数24
期刊KSII Transactions on Internet and Information Systems
4
3
DOI
出版状态已出版 - 30 6月 2010

学术指纹

探究 'Combining adaptive filtering and IF flows to detect DDOS attacks within a router' 的科研主题。它们共同构成独一无二的学术指纹。

引用此