DocumentCode :
3278563
Title :
An Adaptive Sampling Algorithm with Applications to Denial-of-Service Attack Detection
Author :
Patcha, Animesh ; Park, Jung-Min
Author_Institution :
Bradley Dept. of Electr. & Comput. Eng., Virginia Polytech. Inst. & State Univ., Blacksburg, VA
fYear :
2006
fDate :
9-11 Oct. 2006
Firstpage :
11
Lastpage :
16
Abstract :
There is an emerging need for the traffic processing capability of network security mechanisms, such as intrusion detection systems (IDS), to match the high throughput of today´s high-bandwidth networks. Recent research has shown that the vast majority of security solutions deployed today are inadequate for processing traffic at a sufficiently high rate to keep pace with the network´s bandwidth. To alleviate this problem, packet sampling schemes at the front end of network monitoring systems (such as an IDS) have been proposed. However, existing sampling algorithms are poorly suited for this task especially because they are unable to adapt to the trends in network traffic. Satisfying such a criterion requires a sampling algorithm to be capable of controlling its sampling rate to provide sufficient accuracy at minimal overhead. To meet this Utopian goal, adaptive sampling algorithms have been proposed. In this paper, we put forth an adaptive sampling algorithm based on weighted least squares prediction. The proposed sampling algorithm is tailored to enhance the capability of network based IDS at detecting denial-of-service (DoS) attacks. Not only does the algorithm adaptively reduce the volume of data that would be analyzed by an IDS, but it also maintains the intrinsic self-similar characteristic of network traffic. The latter characteristic of the algorithm can be used by an IDS to detect DoS attacks by using the fact that a change in the self-similarity of network traffic is a known indicator of a DoS attack.
Keywords :
Internet; sampling methods; security of data; telecommunication security; telecommunication traffic; adaptive sampling algorithm; denial-of-service attack detection; high-bandwidth networks; intrusion detection systems; network monitoring systems; network security mechanisms; packet sampling schemes; traffic processing capability; weighted least squares prediction; Bandwidth; Change detection algorithms; Communication system traffic control; Computer crime; Intrusion detection; Least squares methods; Monitoring; Sampling methods; Telecommunication traffic; Throughput;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computer Communications and Networks, 2006. ICCCN 2006. Proceedings.15th International Conference on
Conference_Location :
Arlington, VA
ISSN :
1095-2055
Print_ISBN :
1-4244-0572-6
Type :
conf
DOI :
10.1109/ICCCN.2006.286238
Filename :
4067618
Link To Document :
بازگشت