DocumentCode
1581170
Title
Entropy-based input-output traffic mode detection scheme for DoS/DDoS attacks
Author
Tritilanunt, Suratose ; Sivakorn, Suphannee ; Juengjincharoen, Choochern ; Siripornpisan, Ausanee
Author_Institution
Comput. Eng. Dept., Mahidol Univ., Phuttamonthol, Thailand
fYear
2010
Firstpage
804
Lastpage
809
Abstract
Denial-of-service attacks (DoS) and distributed denial-of-service attacks (DDoS) attempt to temporarily disrupt users or computer resources to cause service unavailability to legitimate users in the internetworking system. The most common type of DoS attack occurs when adversaries flood a large amount of bogus data to interfere or disrupt the service on the server. By using a volume-based scheme to detect such attacks, this technique would not be able to inspect short-term denial-of-service attacks, as well as cannot distinguish between heavy load from legitimate users and huge number of bogus messages from attackers. As a result, this paper provides a detection mechanism based on a technique of entropy-based input-output traffic mode detection scheme. The experimental results demonstrate that our approach is able to detect several kinds of denial-of-service attacks, even small spike of such attacks.
Keywords
entropy; internetworking; telecommunication security; telecommunication traffic; DDoS attack; computer resources; distributed denial-of-service attack; entropy-based input-output traffic mode detection; internetworking system; service unavailability; short-term denial-of-service attack; volume-based scheme; Bandwidth; Computer crime; Computers; Entropy; IP networks; Laboratories; Servers; DoS/DDoS attacks; entropy-based detection;
fLanguage
English
Publisher
ieee
Conference_Titel
Communications and Information Technologies (ISCIT), 2010 International Symposium on
Conference_Location
Tokyo
Print_ISBN
978-1-4244-7007-5
Electronic_ISBN
978-1-4244-7009-9
Type
conf
DOI
10.1109/ISCIT.2010.5665097
Filename
5665097
Link To Document