• DocumentCode
    425454
  • Title

    Distributed change detection for worms, DDoS and other network attacks

  • Author

    Cardenas, Alvaro A. ; Baras, John S. ; Ramezani, Vahid

  • Author_Institution
    Dept. of Electr. & Comput. Eng., Maryland Univ., College Park, MD, USA
  • Volume
    2
  • fYear
    2004
  • fDate
    June 30 2004-July 2 2004
  • Firstpage
    1008
  • Abstract
    Self-propagating code (worms) and distributed denial of service (DDoS) attacks are the most frequent and quite devastating attacks on communication networks and the Internet. We provide novel formulations for the rapid detection of these attacks in the control-theoretic framework of change detection. We present algorithms that effectively can detect worms from their temporal spreading characteristics. We describe the effects of the network topology on the algorithms and their performance. We next present algorithms for detecting DDoS while discriminating against changes in the normal traffic. This is accomplished by a distributed detection formalism where a concept of directionality is introduced and exploited. We then turn into attacks to routing protocols in mobile wireless networks. We develop change detection formulations involving hidden Markov models, which match distribution of the number of hops in the mobile and wireless nodes. Using observations that suggest that this distribution is altered substantially in the presence of such attacks we develop and analyze algorithms for their detection.
  • Keywords
    Internet; ad hoc networks; hidden Markov models; invasive software; mobile radio; routing protocols; telecommunication network topology; telecommunication security; telecommunication traffic; Internet; ad hoc networks; communication network attacks; distributed change attack detection; distributed denial of service attacks; hidden Markov models; mobile nodes; mobile wireless networks; network topology effects; network traffic; routing protocols; self propagating code; temporal spreading characteristics; wireless nodes; worms detection;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    American Control Conference, 2004. Proceedings of the 2004
  • Conference_Location
    Boston, MA, USA
  • ISSN
    0743-1619
  • Print_ISBN
    0-7803-8335-4
  • Type

    conf

  • Filename
    1386703