Title :
Entropy-based input-output traffic mode detection scheme for DoS/DDoS attacks
Author :
Tritilanunt, Suratose ; Sivakorn, Suphannee ; Juengjincharoen, Choochern ; Siripornpisan, Ausanee
Author_Institution :
Comput. Eng. Dept., Mahidol Univ., Phuttamonthol, Thailand
Abstract :
Denial-of-service attacks (DoS) and distributed denial-of-service attacks (DDoS) attempt to temporarily disrupt users or computer resources to cause service unavailability to legitimate users in the internetworking system. The most common type of DoS attack occurs when adversaries flood a large amount of bogus data to interfere or disrupt the service on the server. By using a volume-based scheme to detect such attacks, this technique would not be able to inspect short-term denial-of-service attacks, as well as cannot distinguish between heavy load from legitimate users and huge number of bogus messages from attackers. As a result, this paper provides a detection mechanism based on a technique of entropy-based input-output traffic mode detection scheme. The experimental results demonstrate that our approach is able to detect several kinds of denial-of-service attacks, even small spike of such attacks.
Keywords :
entropy; internetworking; telecommunication security; telecommunication traffic; DDoS attack; computer resources; distributed denial-of-service attack; entropy-based input-output traffic mode detection; internetworking system; service unavailability; short-term denial-of-service attack; volume-based scheme; Bandwidth; Computer crime; Computers; Entropy; IP networks; Laboratories; Servers; DoS/DDoS attacks; entropy-based detection;
Conference_Titel :
Communications and Information Technologies (ISCIT), 2010 International Symposium on
Conference_Location :
Tokyo
Print_ISBN :
978-1-4244-7007-5
Electronic_ISBN :
978-1-4244-7009-9
DOI :
10.1109/ISCIT.2010.5665097