Low-Rate DDoS Attack Detection Using Expectation of Packet Size

Joint Authors

Yuan, C.
Zhou, Lu
Liao, Mingchao
Zhang, Haoyu

Source

Security and Communication Networks

Issue

Vol. 2017, Issue 2017 (31 Dec. 2017), pp.1-14, 14 p.

Publisher

Hindawi Publishing Corporation

Publication Date

2017-10-11

Country of Publication

Egypt

No. of Pages

14

Main Subjects

Information Technology and Computer Science

Abstract EN

Low-rate Distributed Denial-of-Service (low-rate DDoS) attacks are a new challenge to cyberspace, as the attackers send a large amount of attack packets similar to normal traffic, to throttle legitimate flows.

In this paper, we propose a measurement—expectation of packet size—that is based on the distribution difference of the packet size to distinguish two typical low-rate DDoS attacks, the constant attack and the pulsing attack, from legitimate traffic.

The experimental results, obtained using a series of real datasets with different times and different tolerance factors, are presented to demonstrate the effectiveness of the proposed measurement.

In addition, extensive experiments are performed to show that the proposed measurement can detect the low-rate DDoS attacks not only in the short and long terms but also for low packet rates and high packet rates.

Furthermore, the false-negative rates and the adjudication distance can be adjusted based on the detection sensitivity requirements.

American Psychological Association (APA)

Zhou, Lu& Liao, Mingchao& Yuan, C.& Zhang, Haoyu. 2017. Low-Rate DDoS Attack Detection Using Expectation of Packet Size. Security and Communication Networks،Vol. 2017, no. 2017, pp.1-14.
https://search.emarefa.net/detail/BIM-1202882

Modern Language Association (MLA)

Zhou, Lu…[et al.]. Low-Rate DDoS Attack Detection Using Expectation of Packet Size. Security and Communication Networks No. 2017 (2017), pp.1-14.
https://search.emarefa.net/detail/BIM-1202882

American Medical Association (AMA)

Zhou, Lu& Liao, Mingchao& Yuan, C.& Zhang, Haoyu. Low-Rate DDoS Attack Detection Using Expectation of Packet Size. Security and Communication Networks. 2017. Vol. 2017, no. 2017, pp.1-14.
https://search.emarefa.net/detail/BIM-1202882

Data Type

Journal Articles

Language

English

Notes

Includes bibliographical references

Record ID

BIM-1202882