IP Packet Size Entropy-Based Scheme for Detection of DoS/DDoS Attacks

IP Packet Size Entropy-Based Scheme for Detection of DoS/DDoS Attacks
复制标题

基于 IP 数据包大小熵的 DoS/DDoS 攻击检测方案

DOI:
10.1093/ietisy/e91-d.5.1274
复制
发表时间:
2008
期刊:
IEICE Trans. Inf. Syst.
影响因子:
--
通讯作者:
S. Abe
S. Abe
中科院分区:
--
文献类型:
--
作者:
P. Du;S. Abe

文献摘要

参考文献

被引文献

相似文献

拒绝服务(DoS)攻击已经成为互联网最严重的威胁之一。检测网络流量中的攻击是一项重要且具有挑战性的任务。然而,大多数现有的基于流量的方案不能检测对流量有轻微影响的短期攻击。另一方面,基于特征的方案不适合实时检测,因为它们的计算复杂。在本文中,我们开发了一种基于IP包大小熵(IPSE)的DoS/DDoS检测方案,其中的熵显着变化时,流量受到攻击。通过我们的分析,我们发现,基于IPSE的计划是能够检测不仅是长期的攻击,但也超出了基于卷的计划的检测能力的短期攻击。此外,我们测试我们的建议使用两个典型的互联网流量数据集从DARPA和SINET,测试结果表明,基于IPSE的检测方案可以提供检测的DoS/DDoS攻击不仅在局域网(DARPA),而且在学术骨干网(SINET)。
Denial of service (DoS) attacks have become one of the most serious threats to the Internet. Enabling detection of attacks in network traffic is an important and challenging task. However, most existing volume-based schemes can not detect short-term attacks that have a minor effect on traffic volume. On the other hand, feature-based schemes are not suitable for real-time detection because of their complicated calculations. In this paper, we develop an IP packet size entropy (IPSE)-based DoS/DDoS detection scheme in which the entropy is markedly changed when traffic is affected by an attack. Through our analysis, we find that the IPSE-based scheme is capable of detecting not only long-term attacks but also short-term attacks that are beyond the volume-based schemes' ability to detect. Moreover, we test our proposal using two typical Internet traffic data sets from DARPA and SINET, and the test results show that the IPSE-based detection scheme can provide detection of DoS/DDoS attacks not only in a local area network (DARPA) and but also in academic backbone network (SINET).
DOI: --
发表时间: 2006
期刊: IT VISION 11
影响因子: --
作者:
紀ノ定保臣;紀ノ定保臣;紀ノ定保臣
通讯作者: 紀ノ定保臣