Sciweavers

ITIIS
2010

Combining Adaptive Filtering and IF Flows to Detect DDoS Attacks within a Router

13 years 11 months ago
Combining Adaptive Filtering and IF Flows to Detect DDoS Attacks within a Router
Traffic matrix-based anomaly detection and DDoS attacks detection in networks are research focus in the network security and traffic measurement community. In this paper, firstly, a new type of unidirectional flow called IF flow is proposed. Merits and features of IF flows are analyzed in detail and then two efficient methods are introduced in our DDoS attacks detection and evaluation scheme. The first method uses residual variance ratio to detect DDoS attacks after Recursive Least Square (RLS) filter is applied to predict IF flows. The second method uses generalized likelihood ratio (GLR) statistical test to detect DDoS attacks after a Kalman filter is applied to estimate IF flows. Based on the two complementary methods, an evaluation formula is proposed to assess the seriousness of current DDoS attacks on router ports. Furthermore, the sensitivity of three types of traffic (IF flow, input link and output link) to DDoS attacks is analyzed and compared. Experiments show that IF flow h...
Ruoyu Yan, Qinghua Zheng, Haifei Li
Added 28 Jan 2011
Updated 28 Jan 2011
Type Journal
Year 2010
Where ITIIS
Authors Ruoyu Yan, Qinghua Zheng, Haifei Li
Comments (0)