A Detection System for Distributed DoS Attacks Based on Automatic Extraction of Normal Mode and Its Performance Evaluation

A Detection System for Distributed DoS Attacks Based on Automatic Extraction of Normal Mode and Its Performance Evaluation
复制标题

基于正常模式自动提取的分布式DoS攻击检测系统及其性能评估

DOI:
10.1007/978-3-319-72389-1_37
复制
发表时间:
2017
期刊:
Proc. of SpaCCS 2017, Springer LNCS
影响因子:
--
通讯作者:
K.Sakurai
K.Sakurai
中科院分区:
--
文献类型:
--
作者:
Y.Feng;Y.Hori;K.Sakurai

文献摘要

相似文献

据报道,分布式拒绝服务(DDoS)攻击,或称DDoS攻击,近年来造成了最严重的损失,并且这种攻击越来越严重。如何有效地检测DDoS攻击自然成为网络安全界最热门的话题之一,并提出了许多方法。然而,现有的检测技术都有自己的弱点。例如,基于信息论的方法必须仔细选择对检测性能起重要作用的信息论度量,并且这种方法只有在数据中存在大量异常时才有效;基于签名的方法不能处理新类型的攻击和现有攻击的新变体等等。然而,它们通常需要一些参数来定义正常节点,并且在许多实际情况下这些参数不容易预先确定。在我们以前的工作中,提出了一种无参数的算法,用于从历史交通数据中提取正常节点。在本文中,我们将解释一个实用的离线检测系统的DDoS攻击,我们开发的基础上,该算法在一个项目称为实践(通过国际合作交流对网络攻击的主动响应)。详细介绍了检测系统的总体流程和主要的具体技术,并通过实例验证了其检测性能。
Distributed DoS (Denial-of-Service) attacks, or say DDoS attacks, have reportedly caused the most serious losses in recent years and such attacks are getting worse. How to efficiently detect DDoS attacks has naturally become one of the hottest topics in the cyber security community and many approaches have been proposed. The existing detection technologies, however, have their own weak points. For example, methods based on information theory must choose an information theoretic measures carefully which play an essential role on the detection performance and such methods are efficient only when there are a significantly large number of anomalies present in the data; signature-based methods can not deal with new kinds of attacks and new variants of existing attacks, and so on. The behavior-based ones have been thought to be promising. However, they often need some parameters to define the normal nodes and such parameters cannot be determined easily in advance in many actual situations. In our previous work, an algorithm without parameters was proposed for extracting normal nodes from the historic traffic data. In this paper, we will explain a practical off-line detection system for DDoS attacks that we developed based on that algorithm in a project called PRACTICE (Proactive Response Against Cyber-attacks Through International Collaborative Exchange). The general flow of our detection system and the main specific technologies are explained in details and its detection performance is also verified by several actual examples.