Low-Rate DoS Attacks Detection Based on Network Multifractal

Low-Rate DoS Attacks Detection Based on Network Multifractal
复制标题

基于网络多重分形的低速率DoS攻击检测

DOI:
10.1109/tdsc.2015.2443807
复制
发表时间:
2016-09-01
影响因子:
7.3
通讯作者:
Yue, Meng
Yue, Meng
中科院分区:
计算机科学2区
文献类型:
--
作者:
Wu, Zhijun;Zhang, Liyuan;Yue, Meng

文献摘要

被引文献

相似文献

低速率拒绝服务(LDoS)攻击以相对较低的速率发送周期性脉冲序列,在受害者端形成聚合流。LDoS攻击流具有平均速率低和隐蔽性强的特点。由于低速率特性,很难从正常流量中检测到LDoS攻击流。网络流量测量表明,聚合网络流量是多重分形的。为了对网络流量进行表征和分析,研究人员开发了简洁的数学模型来探索复杂的多重分形结构。尽管LDoS攻击流非常小,但它必然会导致网络流量多重分形特性的改变。本文旨在利用和评估网络流量多重分形特性的变化来检测LDoS攻击流。采用多重分形去趋势波动分析(MF - DFA)算法来探究由于LDoS攻击在小尺度网络流量上多重分形特性的变化。通过小波分析,利用赫尔德指数估计LDoS攻击下网络流量的奇异性和突发性。计算正常情况和LDoS攻击情况下网络流量赫尔德指数的差值(D值)。以D值作为判断LDoS攻击的依据。根据统计结果设置一个检测阈值。通过比较D值和检测阈值来确定是否存在LDoS攻击。在测试床网络和仿真平台上进行了检测性能实验。大量的实验结果与理论分析一致。
Low-rate denial of service (LDoS) attacks send periodic pulse sequences with relative low rate to form aggregation flows at the victim end. LDoS attack flows have the characteristics of low average rate and great concealment. It is hard to detect LDoS attack flows from normal traffic due to low rate property. Network traffic measurement shows that aggregate network traffic is multifractal. In order to characterize and analyze network traffic, researchers have developed concise mathematical models to explore complex multifractal structure. Although the LDoS attack flows are very small, it will inevitably lead to the change of multifractal characteristics of network traffic. This paper targets at exploiting and estimating the changes in multifractal characteristics of network traffic for detecting LDoS attack flows. The algorithm of multifractal detrended fluctuation analysis (MF-DFA) is used to explore the change in terms of multifractal characteristics over a small scale of network traffic due to LDoS attacks. Through wavelet analysis, the singularity and bursty of network traffic under LDoS attacks are estimated by using Hölder exponent. The difference values (D-value) of Hölder exponent of network traffic between normal and under LDoS attack situations are calculated. The D-value is used as the basis to determine LDoS attacks. A detection threshold is set based on the statistical results. The presence of LDoS attacks can be confirmed through comparing D-value with detection threshold. Experiments on detection performance have been performed in the test-bed network and simulation platform. The extensive experimental results are congruent with the theoretical analysis.