An Unsupervised Approach for Online Detection and Mitigation of High-Rate DDoS Attacks Based on an In-Memory Distributed Graph Using Streaming Data and Analytics

An Unsupervised Approach for Online Detection and Mitigation of High-Rate DDoS Attacks Based on an In-Memory Distributed Graph Using Streaming Data and Analytics
复制标题

基于内存分布式图、使用流数据和分析的无监督在线检测和缓解高速率 DDoS 攻击的方法

DOI:
10.1145/3148055.3148077
复制
发表时间:
2017
期刊:
Applications and Technologies
影响因子:
--
通讯作者:
Parashar, Manish
Parashar, Manish
中科院分区:
--
文献类型:
--
作者:
Villalobos, J. J.;Rodero, Ivan;Parashar, Manish

文献摘要

参考文献

被引文献

相似文献

分布式拒绝服务(DDoS)攻击是一种试图通过使用来自多个来源的流量使在线服务、网络甚至整个组织变得不可用的攻击。DDoS攻击是网络防御者必须警惕的最常见和最具破坏性的威胁之一。DDoS攻击正变得越来越大、越来越频繁、越来越复杂。容量攻击是最常见的DDoS攻击类型。当DDoS攻击在短时间内产生大量的数据包或流量时,可以认为是高容量攻击或高速率攻击。高速率的攻击是众所周知的,并且在过去十年中受到了广泛关注;然而,尽管已经设计和实施了若干检测和缓解战略,但当保护机制无法应对肇事者聚集在一起的总体能力时,高速率攻击仍然使整个互联网的信息技术基础设施停止正常运行。考虑到这一点,本文旨在提出并测试一种分布式协作架构,用于基于内存中的分布式图数据结构和利用实时流数据和分析的无监督机器学习算法的在线高速DDoS攻击检测和缓解。为了再现实际大规模攻击的条件,我们已经使用真实的DDoS攻击数据集以其原始速率成功测试了我们提出的机制。
A Distributed Denial of Service (DDoS) attack is an attempt to make an online service, a network, or even an entire organization, unavailable by saturating it with traffic from multiple sources. DDoS attacks are among the most common and most devastating threats that network defenders have to watch out for. DDoS attacks are becoming bigger, more frequent, and more sophisticated. Volumetric attacks are the most common types of DDoS attacks. A DDoS attack is considered volumetric, or high-rate, when within a short period of time it generates a large amount of packets or a high volume of traffic. High-rate attacks are well-known and have received much attention in the past decade; however, despite several detection and mitigation strategies have been designed and implemented, high-rate attacks are still halting the normal operation of information technology infrastructures across the Internet when the protection mechanisms are not able to cope with the aggregated capacity that the perpetrators have put together. With this in mind, the present paper aims to propose and test a distributed and collaborative architecture for online high-rate DDoS attack detection and mitigation based on an in-memory distributed graph data structure and unsupervised machine learning algorithms that leverage real-time streaming data and analytics. We have successfully tested our proposed mechanism using a real-world DDoS attack dataset at its original rate in pursuance of reproducing the conditions of an actual large scale attack.
计算滑动窗口上的不同元素
DOI: --
发表时间: 2017
期刊: Annual Haifa Experimental Systems Conference
影响因子: --
作者:
Eran Assaf;R. Ben;Gil Einziger;R. Friedman;Yaron Kassner
通讯作者: Yaron Kassner
基于数据包分析和支持向量机的智能DDoS攻击检测系统
DOI: --
发表时间: 2014
期刊:
影响因子: --
作者:
Keisuke Kato;V. Klyuev
通讯作者: V. Klyuev
DOI: 10.1145/2987443.2987487
发表时间: 2016-11
期刊: Proceedings of the 2016 Internet Measurement Conference
影响因子: --
作者:
M. Jonker;A. Sperotto;R. V. Rijswijk-Deij;R. Sadre;A. Pras
通讯作者: M. Jonker;A. Sperotto;R. V. Rijswijk-Deij;R. Sadre;A. Pras
DOI: --
发表时间: 2012
期刊: IEEE International Conference on Mobile Adhoc and Sensor Systems
影响因子: --
作者:
Z. Han;Xiaofeng Wang;Fei Wang;Yongjun Wang
通讯作者: Yongjun Wang
STONE:基于流的 DDoS 防御框架
DOI: --
发表时间: 2013
期刊: ACM Symposium on Applied Computing
影响因子: --
作者:
Mar Callau;R. Jiménez;Vincenzo Gulisano;M. Papatriantafilou;Zhang Fu;M. Patiño
通讯作者: M. Patiño