Detection of stealthy TCP-based DoS attacks

Detection of stealthy TCP-based DoS attacks
复制标题

检测基于 TCP 的隐秘 DoS 攻击

DOI:
10.1109/milcom.2015.7357467
复制
发表时间:
2015
期刊:
MILCOM 2015 - 2015 IEEE Military Communications Conference
影响因子:
--
通讯作者:
A. Swami
A. Swami
中科院分区:
--
文献类型:
--
作者:
Azeem Aqil;A. Atya;T. Jaeger;S. Krishnamurthy;K. Levitt;P. Mcdaniel;J. Rowe;A. Swami

文献摘要

被引文献

相似文献

拒绝服务(DoS)攻击是最严重的网络攻击之一,因为它们很容易编排,通常会导致目标资源立即关闭。今天的入侵检测系统检查特定的单个标量特征是否超过阈值,以确定是否正在进行特定的基于TCP的DoS攻击。为了击败这样的系统,我们证明了攻击者可以简单地发起攻击线程的组合,其中每个线程本身不会破坏系统,但在一起可以非常强大。我们证明,这种攻击不能被检测到简单的基于阈值的统计异常检测技术,在今天的入侵检测系统中使用。我们认为,一个有效的方法来检测这种攻击是通过共同考虑多个功能,这些攻击的影响。在此基础上,我们确定了一组可能的这样的功能,并设计了一个新的检测方法,共同检查这些功能,是否每个超过一个高阈值或低于一个低阈值。我们证明,这种方法是非常有效的检测隐形拒绝服务攻击,真阳性率接近100%,假阳性率降低了约66%,相比传统的检测器。
Denial of service (DoS) attacks are among the most crippling of network attacks because they are easy to orchestrate and usually cause an immediate shutdown of whatever resource is targeted. Today's intrusion detection systems check if specific single scalar features exceed a threshold to determine if a specific TCP-based DoS attack is underway. To defeat such systems we demonstrate that an attacker can simply launch a combination of attack threads, each of which on its own does not break a system down but together can be very potent. We demonstrate that such attacks cannot be detected by simple threshold based statistical anomaly detection techniques that are used in today's intrusion detection systems. We argue that an effective way to detect such attacks is by jointly considering multiple features that are affected by such attacks. Based on this, we identify a possible set of such features and design a new detection approach that jointly examines these features with regards to whether each exceeds a high threshold or is below a low threshold. We demonstrate that this approach is extremely effective in detecting stealthy DoS attacks; the true positive rate is close to 100 % and the false positive rate is decreased by about 66 % as compared to traditional detectors.