DocumentCode :
2939792
Title :
DDoS Attack Detection Using IP Address Feature Interaction
Author :
Cheng, JieRen ; Yin, Jianping ; Liu, Yun ; Cai, Zhiping ; Wu, Chengkun
Author_Institution :
Sch. of Comput., Nat. Univ. of Defense Technol., Changsha, China
fYear :
2009
fDate :
4-6 Nov. 2009
Firstpage :
113
Lastpage :
118
Abstract :
Distributed denial-of-service (DDoS) attacks present serious threats to servers in the Internet. We argue that the difference of the goals, manners and results of the interaction behaviors of normal flows and attack flows, which show different characteristics on IP addresses and ports. IAI (IP Address Interaction Feature) algorithm is proposed based on the addresses interaction, abrupt traffic change, addresses many-to-one dissymmetry, distributed source IP addresses and concentrated target addresses. The IAI is designed to describe the essential characteristics of network flow states. Furthermore, a support vector machine (SVM) classifier, which is trained by IAI time series from normal flow and attack flow, is applied to classify the state of current network flows and identify the DDoS attacks. The experiment results show that, IAI can reflect the different characteristics of DDoS attack flows and normal flows; the IAI-based detection scheme can distinguish between normal flows and abnormal flows with DDoS attack flows effectively, and help to identify fast and accurate attack flows when the attacking traffic is hidden among a relatively large volume of normal flows or close to the attacking sources, and it has higher detection and lower false alarm rate compared with related works.
Keywords :
Internet; security of data; support vector machines; DDoS attack detection; IP address interaction feature algorithm; Internet protocol; distributed denial-of-service; support vector machine; Computer crime; Computer networks; Distributed computing; Intelligent networks; International collaboration; Network servers; Support vector machine classification; Support vector machines; Telecommunication traffic; Traffic control; Distributed Denial of Service; IP Address Interaction Feature; Network Security; SVM classifier;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Intelligent Networking and Collaborative Systems, 2009. INCOS '09. International Conference on
Conference_Location :
Barcelona
Print_ISBN :
978-1-4244-5165-4
Electronic_ISBN :
978-0-7695-3858-7
Type :
conf
DOI :
10.1109/INCOS.2009.34
Filename :
5370928
Link To Document :
بازگشت