DocumentCode
425454
Title
Distributed change detection for worms, DDoS and other network attacks
Author
Cardenas, Alvaro A. ; Baras, John S. ; Ramezani, Vahid
Author_Institution
Dept. of Electr. & Comput. Eng., Maryland Univ., College Park, MD, USA
Volume
2
fYear
2004
fDate
June 30 2004-July 2 2004
Firstpage
1008
Abstract
Self-propagating code (worms) and distributed denial of service (DDoS) attacks are the most frequent and quite devastating attacks on communication networks and the Internet. We provide novel formulations for the rapid detection of these attacks in the control-theoretic framework of change detection. We present algorithms that effectively can detect worms from their temporal spreading characteristics. We describe the effects of the network topology on the algorithms and their performance. We next present algorithms for detecting DDoS while discriminating against changes in the normal traffic. This is accomplished by a distributed detection formalism where a concept of directionality is introduced and exploited. We then turn into attacks to routing protocols in mobile wireless networks. We develop change detection formulations involving hidden Markov models, which match distribution of the number of hops in the mobile and wireless nodes. Using observations that suggest that this distribution is altered substantially in the presence of such attacks we develop and analyze algorithms for their detection.
Keywords
Internet; ad hoc networks; hidden Markov models; invasive software; mobile radio; routing protocols; telecommunication network topology; telecommunication security; telecommunication traffic; Internet; ad hoc networks; communication network attacks; distributed change attack detection; distributed denial of service attacks; hidden Markov models; mobile nodes; mobile wireless networks; network topology effects; network traffic; routing protocols; self propagating code; temporal spreading characteristics; wireless nodes; worms detection;
fLanguage
English
Publisher
ieee
Conference_Titel
American Control Conference, 2004. Proceedings of the 2004
Conference_Location
Boston, MA, USA
ISSN
0743-1619
Print_ISBN
0-7803-8335-4
Type
conf
Filename
1386703
Link To Document