Title :
Distributed change detection for worms, DDoS and other network attacks
Author :
Cardenas, Alvaro A. ; Baras, John S. ; Ramezani, Vahid
Author_Institution :
Dept. of Electr. & Comput. Eng., Maryland Univ., College Park, MD, USA
fDate :
June 30 2004-July 2 2004
Abstract :
Self-propagating code (worms) and distributed denial of service (DDoS) attacks are the most frequent and quite devastating attacks on communication networks and the Internet. We provide novel formulations for the rapid detection of these attacks in the control-theoretic framework of change detection. We present algorithms that effectively can detect worms from their temporal spreading characteristics. We describe the effects of the network topology on the algorithms and their performance. We next present algorithms for detecting DDoS while discriminating against changes in the normal traffic. This is accomplished by a distributed detection formalism where a concept of directionality is introduced and exploited. We then turn into attacks to routing protocols in mobile wireless networks. We develop change detection formulations involving hidden Markov models, which match distribution of the number of hops in the mobile and wireless nodes. Using observations that suggest that this distribution is altered substantially in the presence of such attacks we develop and analyze algorithms for their detection.
Keywords :
Internet; ad hoc networks; hidden Markov models; invasive software; mobile radio; routing protocols; telecommunication network topology; telecommunication security; telecommunication traffic; Internet; ad hoc networks; communication network attacks; distributed change attack detection; distributed denial of service attacks; hidden Markov models; mobile nodes; mobile wireless networks; network topology effects; network traffic; routing protocols; self propagating code; temporal spreading characteristics; wireless nodes; worms detection;
Conference_Titel :
American Control Conference, 2004. Proceedings of the 2004
Conference_Location :
Boston, MA, USA
Print_ISBN :
0-7803-8335-4