Detecting LDoS Attacks based on Abnormal Network Traffic

Detecting LDoS Attacks based on Abnormal Network Traffic
复制标题

DOI:
10.3837/tiis.2012.07.007
复制
发表时间:
2012-07
期刊:
KSII Trans. Internet Inf. Syst.
影响因子:
--
通讯作者:
Kai Chen;Huiyu Liu;Xiaosu Chen
Kai Chen;Huiyu Liu;Xiaosu Chen
中科院分区:
其他
文献类型:
--
作者:
Kai Chen;Huiyu Liu;Xiaosu Chen

文献摘要

被引文献

相似文献

By sending periodically short bursts of traffic to reduce legit transmission control protocol (TCP) traffic, the low-rate denial of service (LDoS) attacks are hard to be detected and may endanger covertly a network for a long period. Traditionally, LDoS detecting methods mainly concentrate on the attack stream with feature matching, and only a limited number of attack patterns can be detected off-line with high cost. Recent researches divert focus from the attack stream to the traffic anomalies induced by LDoS attacks, which can detect more kinds of attacks with higher efficiency. However, the limited number of abnormal characteristics and the inadequacy of judgment rules may cause wrong decision in some particular situations. In this paper, we address the problem of detecting LDoS attacks and present a scheme based on the fluctuant features of legit TCP and acknowledgment (ACK) traffic. In the scheme, we define judgment criteria which used to identify LDoS attacks in real time at an optimal detection cost. We evaluate the performance of our strategy in real-world network topologies. Simulations results clearly demonstrate the superiority of the method proposed in detecting LDoS attacks.