SEDP‐based detection of low‐rate DoS attacks

SEDP‐based detection of low‐rate DoS attacks
复制标题

DOI:
10.1002/dac.2783
复制
发表时间:
2015-07
影响因子:
2.1
通讯作者:
Zhi-jun Wu;Meng Yue;Douzhe Li;Ke Xie
Zhi-jun Wu;Meng Yue;Douzhe Li;Ke Xie
中科院分区:
计算机科学4区
文献类型:
--
作者:
Zhi-jun Wu;Meng Yue;Douzhe Li;Ke Xie

文献摘要

被引文献

相似文献

低速率拒绝服务(LDOS)是一种新型的以TCP为目标的攻击,它试图拒绝对TCP流的带宽,同时以足够低的平均速率发送以躲避DoS防御系统的检测。因此,LDOS攻击很难被路由器和反DoS机制检测到。提出了一种基于谱能量分布概率模型的信号处理技术来检测LDOS攻击的方法。该方法利用数据包采样序列计算在一定时间内正常传输协议的入站流量与服务器的攻击流之间的方差。将网络流量从时间域转换到频域,形成频谱信号,并基于矩形脉冲的频谱特性估计频谱能量的分布概率。该方法发现,LDOS攻击的能量主要分布在主瓣宽度上,而正常的TCP流量的能量在频域上仅集中在零附近。计算分布在主瓣上的正常TCP流量和LDOS攻击的频谱能量,并根据能量分布特性,根据统计结果设置能量阈值作为决策值。通过将计算的方差与预设的判决阈值进行比较来确定和检测LDOS攻击的存在。在NS-2仿真环境下对该方法的检测性能进行了测试,并通过假设检验得到了检测率。实验结果表明,该方法具有较高的检测精度和较小的计算量。版权所有©2014 John Wiley&Sons,Ltd.
Low‐rate Denial of Service (LDoS) is a new type of TCP‐targeted attacks, which attempt to deny bandwidth to TCP flows while sending at sufficiently low‐average rate to elude detection of DoS defense system. Therefore, LDoS attacks are difficult to be detected by routers and counter‐DoS mechanisms. In this paper, an approach of detecting LDoS attacks is proposed by using the technology of signal processing based on the model of spectral energy distribution probability. The proposed approach calculates variances between the incoming traffic of normal TCP and attack flows to a server by using packet sampling sequence within a certain period. The network traffic is converted from the time domain to the frequency domain forming a spectral signal, and the distribution probability of spectral energy is estimated based on spectrum characteristics of rectangular pulses. This approach explores that the energy of LDoS attacks is mostly distributed in the main lobe width while that of normal TCP traffic is just concentrated near zero in frequency domain. Both the spectral energy of normal TCP traffic and LDoS attacks distributed in main lobe are calculated, and an energy threshold is set as decision value based on statistical results according to energy distribution properties. The existence of LDoS attacks is determined and detected by comparing calculated variances with the preset decision threshold value. Tests on the detection performance of the proposed approach were performed in NS‐2 simulation environment, and detection rate was obtained by Hypothesis test. Experiment results show that the proposed approach has higher detection accuracy and less computation consuming. Copyright © 2014 John Wiley & Sons, Ltd.