DocumentCode
2760624
Title
Global detection of DDoS attack based on time and frequency analysis
Author
Luo Hua ; Hu Guang-min ; Yao Xing-miao
Author_Institution
Univ. of Electron. Sci. & Technol. of China, Chengdu
fYear
2007
fDate
11-13 July 2007
Firstpage
462
Lastpage
466
Abstract
Due to the complicated and distributed characters of DDoS attack, a novel detection DDoS method based on global network is presented in this paper. Our method detects DDoS by analyzing network-wide traffic, whereas the traditional methods detect it on single link or victim network, they can only detect the DDoS which show large scope. Our method was carried out as follows: First, we get network traffic matrix. Then we diagnose DDoS in time domain and frequency domain by K-L transformation and computing correlation coefficient. K-L divides time domain and frequency domain sequence into normal space and abnormal space and then we compute the abnormal space´s correlation coefficient. Finally, we set threshold to detect DDoS attack. The simulation result shows that some DDoS could be detected in time domain but others could only be detected in frequency domain. This method is more accurate and faster than traditional ones. It is well suited for detecting earlier DDoS attack.
Keywords
Internet; matrix algebra; telecommunication security; telecommunication traffic; time-frequency analysis; DDoS attack detection; Internet; K-L transformation; correlation coefficient; frequency domain analysis; network traffic matrix; time domain analysis; Correlation; Time frequency analysis;
fLanguage
English
Publisher
ieee
Conference_Titel
Communications, Circuits and Systems, 2007. ICCCAS 2007. International Conference on
Conference_Location
Kokura
Print_ISBN
978-1-4244-1473-4
Type
conf
DOI
10.1109/ICCCAS.2007.6251606
Filename
6251606
Link To Document