Low-Rate DoS Attacks Detection Based on MAF-ADM

Low-Rate DoS Attacks Detection Based on MAF-ADM
复制标题

基于MAF-ADM的低速率DoS攻击检测

DOI:
10.3390/s20010189
复制
发表时间:
2020-01-01
期刊:
影响因子:
3.9
通讯作者:
Wang, Xiyin
Wang, Xiyin
中科院分区:
综合性期刊3区
文献类型:
--
作者:
Zhan, Sijia;Tang, Dan;Wang, Xiyin

文献摘要

被引文献

相似文献

低速率拒绝服务(LDoS)攻击通过向瓶颈路由器发送周期性的数据包突发来降低网络服务质量。由于其隐蔽性和低平均攻击流量行为,很难被反拒绝服务机制检测到。针对LDoS攻击,提出了一种基于自适应多特征融合的异常检测方法(MAF-ADM)。该研究是基于这样一个事实,即合法的传输控制协议(TCP)流量的时间-频率联合分布会改变LDoS攻击。选取时频联合分布的多个统计指标生成孤立树,该孤立树能同时反映时域和频域的异常。然后,我们根据所有隔离树隔离包含LDoS攻击的样本的能力,通过融合所有隔离树的结果来计算异常评分。最后,采用加权移动平均算法对异常值进行平滑处理,避免网络中噪声带来的误差。在网络模拟器2(NS2)、测试平台和公共数据集(WIDE2018和LBNL)上的实验结果表明,该方法能够有效检测LDoS攻击,且误报率较低。
Low-rate denial of service (LDoS) attacks reduce the quality of network service by sending periodical packet bursts to the bottleneck routers. It is difficult to detect by counter-DoS mechanisms due to its stealthy and low average attack traffic behavior. In this paper, we propose an anomaly detection method based on adaptive fusion of multiple features (MAF-ADM) for LDoS attacks. This study is based on the fact that the time-frequency joint distribution of the legitimate transmission control protocol (TCP) traffic would be changed under LDoS attacks. Several statistical metrics of the time-frequency joint distribution are chosen to generate isolation trees, which can simultaneously reflect the anomalies in time domain and frequency domain. Then we calculate anomaly score by fusing the results of all isolation trees according to their ability to isolate samples containing LDoS attacks. Finally, the anomaly score is smoothed by weighted moving average algorithm to avoid errors caused by noise in the network. Experimental results of Network Simulator 2 (NS2), testbed, and public datasets (WIDE2018 and LBNL) demonstrate that this method does detect LDoS attacks effectively with lower false negative rate.