• DocumentCode
    3164788
  • Title

    A covariance analysis model for DDoS attack detection

  • Author

    Jin, Shuyuan ; Yeung, Daniel S.

  • Author_Institution
    Dept. of Comput., Hong Kong Polytech. Univ., China
  • Volume
    4
  • fYear
    2004
  • fDate
    20-24 June 2004
  • Firstpage
    1882
  • Abstract
    This paper discusses the effects of multivariate correlation analysis on the DDoS detection and proposes an example, a covariance analysis model for detecting SYN flooding attacks. The simulation results show that this method is highly accurate in detecting malicious network traffic in DDoS attacks of different intensities. This method can effectively differentiate between normal and attack traffic. Indeed, this method can detect even very subtle attacks only slightly different from the normal behaviors. The linear complexity of the method makes its real time detection practical. The covariance model in this paper to some extent verifies the effectiveness of multivariate correlation analysis for DDoS detection. Some open issues still exist in this model for further research.
  • Keywords
    computational complexity; computer networks; correlation methods; covariance analysis; telecommunication security; telecommunication services; telecommunication traffic; DDoS attack detection; attack traffic; covariance analysis model; distributed denial of service; flooding attacks; linear complexity; multivariate correlation analysis; network traffic; Clustering methods; Computational modeling; Computer crime; Entropy; Floods; Protocols; Statistical analysis; Telecommunication traffic; Traffic control; Web server;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Communications, 2004 IEEE International Conference on
  • Print_ISBN
    0-7803-8533-0
  • Type

    conf

  • DOI
    10.1109/ICC.2004.1312847
  • Filename
    1312847