Statistical measures: Promising features for time series based DDoS attack detection

Statistical measures: Promising features for time series based DDoS attack detection
复制标题

统计措施:基于时间序列的 DDoS 攻击检测的有前途的功能

DOI:
10.1109/siu.2018.8404348
复制
发表时间:
2018
期刊:
2018 26th Signal Processing and Communications Applications Conference (SIU)
影响因子:
--
通讯作者:
E. Anarim
E. Anarim
中科院分区:
--
文献类型:
--
作者:
Cemil Eren Kayatas;R. Fouladi;Orhan Ermis;E. Anarim

文献摘要

被引文献

相似文献

通信技术的广泛使用增加了对保证通信系统可用性的高质量和可靠服务的需求。然而,由于分布式拒绝服务(DDoS)攻击的存在,提供服务的可用性是一个具有挑战性的问题。在DDoS攻击中,攻击者伪装成合法用户,试图增加流量以降低主机和服务器之间通信的服务质量。虽然入侵检测系统用于检测DDoS攻击,但由于攻击者发送的数据包与正常数据包相似,因此无法检测。因此,从传统的基于数据包的分析方法转向基于时间序列的(基于流的)算法将是一种更好的、有前途的替代方案,以发现DDoS攻击。在本研究中,我们使用时间序列的峰度和偏度度量来研究这些参数的性能,以区分DDoS攻击和正常流量。
The pervasive use of communication technologies increases the demand for high quality and reliable services which guarantees the availability of a communication system. However, providing the availability of services is a challenging issue due to the existence of Distributed Denial of Service (DDoS) attacks. In DDoS attacks, an attacker, who masquerade itself as a legitimate user, tries to increase in the volume of traffic to degrade the Quality of Service of a communication between hosts and the server. Although intrusion detection systems are used to detect DDoS attacks, they are impotent of detection since packets similar to normal ones are dispatched by the attacker. Therefore, transferring from conventional packet-based analysis methods to time series based (flow-based) algorithms would be a better and promising alternative to spot DDoS attacks. In this study, we use kurtosis and skewness measures of a time series to investigate the performance of these parameters for distinguishing a DDoS attack from a normal traffic.