A Rank Correlation Based Detection against Distributed Reflection DoS Attacks

A Rank Correlation Based Detection against Distributed Reflection DoS Attacks
复制标题

DOI:
10.1109/lcomm.2012.121912.122257
复制
发表时间:
2013-01
期刊:
IEEE Communications Letters
影响因子:
--
通讯作者:
Wei Wei-Wei;F. Chen;Yingjie Xia;Guang Jin
Wei Wei-Wei;F. Chen;Yingjie Xia;Guang Jin
中科院分区:
其他
文献类型:
--
作者:
Wei Wei-Wei;F. Chen;Yingjie Xia;Guang Jin

文献摘要

被引文献

相似文献

DDoS自出现以来就对互联网构成了严重的威胁,许多受控主机向受害者站点发送大量数据包。此外,在分布式反射拒绝服务(DRDoS)中,攻击者欺骗无辜的服务器(反射器)将数据包刷新到受害者。但目前的DRDoS检测机制大多与特定的协议相关联,不能用于未知的协议。研究发现,由于受到同一攻击流的激励,来自反射器的响应流之间存在着内在的联系:一个收敛响应流的包速率与另一个收敛响应流的包速率之间可能存在线性关系。在此基础上,提出了基于秩相关的检测算法(RCD)。初步的仿真结果表明,RCD可以有效区分反射流和合法流,从而可以作为一个可用的DRDoS的指标。
DDoS presents a serious threat to the Internet since its inception, where lots of controlled hosts flood the victim site with massive packets. Moreover, in Distributed Reflection DoS (DRDoS), attackers fool innocent servers (reflectors) into flushing packets to the victim. But most of current DRDoS detection mechanisms are associated with specific protocols and cannot be used for unknown protocols. It is found that because of being stimulated by the same attacking flow, the responsive flows from reflectors have inherent relations: the packet rate of one converged responsive flow may have linear relationships with another. Based on this observation, the Rank Correlation based Detection (RCD) algorithm is proposed. The preliminary simulations indicate that RCD can differentiate reflection flows from legitimate ones efficiently and effectively, thus can be used as a useable indicator for DRDoS.