Concepedia

Publication | Closed Access

Statistical approaches to DDoS attack detection and response

498

Citations

12

References

2004

Year

TLDR

DDoS attacks threaten large networks such as the Internet, exhibiting anomalies in selected packet attributes that necessitate effective detection and response methods. The paper aims to present methods for identifying DDoS attacks using entropy and frequency‑sorted distributions of selected packet attributes, deployable at both edge and core network locations. The authors compute entropy and frequency‑sorted distributions of selected packet attributes, evaluate detection accuracy and performance on live traffic traces from core and edge networks, and describe a detection‑response prototype that can be extended for effective response decisions. The methods achieve effective detection accuracy on live traffic traces from core and edge networks, and the results suggest directions for improving detection of more stealthy attacks.

Abstract

The nature of the threats posed by distributed denial of service (DDoS) attacks on large networks, such as the Internet, demands effective detection and response methods. These methods must be deployed not only at the edge but also at the core of the network This paper presents methods to identify DDoS attacks by computing entropy and frequency-sorted distributions of selected packet attributes. The DDoS attacks show anomalies in the characteristics of the selected packet attributes. The detection accuracy and performance are analyzed using live traffic traces from a variety of network environments ranging from points in the core of the Internet to those inside an edge network The results indicate that these methods can be effective against current attacks and suggest directions for improving detection of more stealthy attacks. We also describe our detection-response prototype and how the detectors can be extended to make effective response decisions.

References

YearCitations

Page 1