DocumentCode :
2520089
Title :
On the Detection of DDoS Attackers for Large-Scale Networks
Author :
Nashat, Dalia ; Jiang, Xiaohong ; Horiguchi, Susumu
Author_Institution :
Grad. Sch. of Inf. Sci., Tohoku Univ., Sendai, Japan
fYear :
2009
fDate :
21-23 Oct. 2009
Firstpage :
206
Lastpage :
212
Abstract :
The distributed denial of service attacks (DDoS) is one of the major threats to network security that exhausts network bandwidth and resources. The current detection schemes are sensitive to the number of attackers and may lead to a high false positive probability especially for large-scale networks with huge number of attackers. It is notable, however, that in the current DDoS attacks, the flooding rate is usually distributed among many flooding sources to make the detection more difficult. In this paper we propose a more efficient detection scheme for Web service DDoS attackers. The proposed scheme is based on the number of incoming requests to the server with the consideration of the clients activity (active and non-active clients during the detection time). To make our scheme scalable to large-scale networks, the non-adaptive group testing theory is applied to detect attackers using low state overhead. Extensive trace-driven simulation has been conducted on real Web trace to demonstrate the efficiency of the proposed scheme in terms of its false positive, false negative probabilities and also detection time.
Keywords :
Web services; client-server systems; probability; security of data; DDoS attack detection; Web service; client-server system; distributed denial of service; false negative probability; flooding rate; high false positive probability; large-scale network; network bandwidth; network resource; network security; nonadaptive group testing theory; trace-driven simulation; Application software; Bandwidth; Computer crime; Floods; Information security; Internet; Large-scale systems; Network servers; Testing; Web services;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
e-Business Engineering, 2009. ICEBE '09. IEEE International Conference on
Conference_Location :
Macau
Print_ISBN :
978-0-7695-3842-6
Type :
conf
DOI :
10.1109/ICEBE.2009.35
Filename :
5342111
Link To Document :
بازگشت