DocumentCode
2642808
Title
Adaptive DDoS Detector Design Using Fast Entropy Computation Method
Author
No, Giseop ; Ra, Ilkyeun
Author_Institution
Sch. of Comput. Sci. & Eng., Seoul Nat. Univ., Seoul, South Korea
fYear
2011
fDate
June 30 2011-July 2 2011
Firstpage
86
Lastpage
93
Abstract
Recently, the threat of DDoS (Distributed Denial-of-Service) attacks is growing continuously and acquiring attacking tools via Internet is getting easy. One of the researches introduced a fast method to detect attacks using modified information entropy (so called Fast Entropy). Fast Entropy shows the significant reduce of computational time compared to conventional entropy computation while it maintains detection accuracy. However, Fast Entropy needs the manual threshold settings during detection process which is not realistic in real detection facility. We introduce adaptive detector with dynamic detection window size and adaptive threshold shifting using Fast Entropy, called AFEA (Adaptive DDoS attack detection using Fast Entropy Approach). Our adaptive DDoS detector successfully demonstrates that its performance of the DDoS detection can be enhanced by the best result of Fast Entropy detection scheme without manual threshold setting and system training while it maintains the same computational time of Fast Entropy detection scheme. In addition, we found that Dynamic AFEA can enhance detection level more than fixed (non-dynamic) one when it is equipped with Fast Entropy.
Keywords
Internet; entropy; security of data; Internet; adaptive DDoS attack detection using fast entropy approach; adaptive threshold shifting; distributed denial-of-service attacks; dynamic detection window size; Accuracy; Computer crime; Detectors; Entropy; IP networks; Internet; Monitoring; DDoS; Dynamic Adaptive Detector; Entropy based approach; Fast Infromatin Entropy;
fLanguage
English
Publisher
ieee
Conference_Titel
Innovative Mobile and Internet Services in Ubiquitous Computing (IMIS), 2011 Fifth International Conference on
Conference_Location
Seoul
Print_ISBN
978-1-61284-733-7
Electronic_ISBN
978-0-7695-4372-7
Type
conf
DOI
10.1109/IMIS.2011.82
Filename
5976144
Link To Document