DocumentCode :
2704746
Title :
An Improvement on Precision in DDoS Source-End Detection with Multi-stream Combined HMM
Author :
Kang, Jian ; Li, Qiang ; Zhang, Yuan ; Li, Zhuo
Author_Institution :
Jilin Univ., Changchun
fYear :
2007
fDate :
15-19 Dec. 2007
Firstpage :
514
Lastpage :
517
Abstract :
DDoS (distributed denial-of-service) attacks detection system deployed in source-end network is superior in perceiving and throttling attacks before dataflows enter Internet, comparing with that in victim network. However, the current existed works in source- end network are so fragile, lead to a high false-positive rate and false-negative rate. This paper proposes a novel approach using multi-stream combined hidden Markov model (MC-HMM) on source-end DDoS detection for integrating multi-features simultaneously. The multi-features include the S-D-P three-tuple, TCP header Flags, and IP header ID field. Through experiments, we compared our original approach based on multiple detection features with other algorithms (such as CUSUM and HMM). The results present that our approach effectively reduces false-positive rate and false-negative rate, and improves the precision of detection.
Keywords :
Internet; hidden Markov models; security of data; DDoS source-end detection; HMM; IP header ID field; Internet; TCP header flags; detection system; distributed denial-of-service attacks; false-negative rate; false-positive rate; multiple detection features; multistream combined hidden Markov model; Change detection algorithms; Computational intelligence; Computer crime; Computer science; Computer security; Data mining; Hidden Markov models; IP networks; Packaging; TCPIP;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computational Intelligence and Security Workshops, 2007. CISW 2007. International Conference on
Conference_Location :
Harbin
Print_ISBN :
978-0-7695-3073-4
Type :
conf
DOI :
10.1109/CISW.2007.4425546
Filename :
4425546
Link To Document :
بازگشت