Title :
Spatial correlation detection of DDoS attack
Author :
Li, Zonglin ; Hu, Guangming ; Yao, Xingmiao
Author_Institution :
Key Lab. of Broadband Opt. Fiber Transm. & Commun. Networks, Univ. of Electron. Sci. & Technol. of China (UESTC), Chengdu, China
Abstract :
DDoS attack flows distributed in many links exhibit directional nature, they are usually generated by certain tools and originate from different nodes, but have inherent dependencies in spatial when transit in network. This will cause correlation between the traffic where they traverse deviate from norm. By taking advantage of this feature, we propose a spatial correlation detection method deploying in backbone network to combat DDoS attack. In doing so, we first approximately estimate abnormality of every origin destination (OD) flow through comparing observations with predictions, then for OD flows with same destination, extracting spatial correlation between their abnormality estimations by principle component analysis(PCA). Abrupt change of spatial correlation indicates DDoS attack occurs. We evaluate the detection performance of our method in detecting synthetic DDoS attack that injected on real backbone traffic through receiver operating characteristic (ROC) curve. The contribution of this paper is utilizing spatial correlation between attack flows, rather than the volume of attack purely, facilitates us to detect relatively small attack being masked in tremendous traffic of backbone network. Moreover, contrary to the centralized computation of previous network-wide anomaly detection method, our method can be deployed separately in each node, in such a way that our method can adapt to different size of network, and thus scalable.
Keywords :
approximation theory; principal component analysis; telecommunication security; telecommunication traffic; DDoS attack; approximation theory; backbone network; network traffic; origin destination flow; principle component analysis; receiver operating characteristic curve; spatial correlation detection; Aggregates; Bandwidth; Communication networks; Computer crime; Computer networks; Floods; Optical fiber dispersion; Optical fibers; Spine; Telecommunication traffic;
Conference_Titel :
Communications, Circuits and Systems, 2009. ICCCAS 2009. International Conference on
Conference_Location :
Milpitas, CA
Print_ISBN :
978-1-4244-4886-9
Electronic_ISBN :
978-1-4244-4888-3
DOI :
10.1109/ICCCAS.2009.5250511