首页 | 本学科首页   官方微博 | 高级检索  
     


Denial of service detection using dynamic time warping
Authors:Diab M. Diab  Basil AsSadhan  Hamad Binsalleeh  Sangarapillai Lambotharan  Konstantinos G. Kyriakopoulos  Ibrahim Ghafir
Affiliation:1. Department of Computer Science, King Saud University, Riyadh, Saudi Arabia;2. Department of Electrical Engineering, King Saud University, Riyadh, Saudi Arabia;3. Department of Computer Science, Imam Mohammad Ibn Saud Islamic University, Riyadh, Saudi Arabia;4. Wolfson School of Mechanical, Electrical and Manufacturing Engineering, Loughborough University, Loughborough, UK;5. Department of Computer Science, University of Bradford, Bradford, UK
Abstract:With the rapid growth of security threats in computer networks, the need for developing efficient security-warning systems is substantially increasing. Distributed denial-of-service (DDoS) and DoS attacks are still among the most effective and dreadful attacks that require robust detection. In this work, we propose a new method to detect TCP DoS/DDoS attacks. Since analyzing network traffic is a promising approach, our proposed method utilizes network traffic by decomposing the TCP traffic into control and data planes and exploiting the dynamic time warping (DTW) algorithm for aligning these two planes with respect to the minimum Euclidean distance. By demonstrating that the distance between the control and data planes is considerably small for benign traffic, we exploit this characteristic for detecting attacks as outliers. An adaptive thresholding scheme is implemented by adjusting the value of the threshold in accordance with the local statistics of the median absolute deviation (MAD) of the distances between the two planes. We demonstrate the efficacy of the proposed method for detecting DoS/DDoS attacks by analyzing traffic data obtained from publicly available datasets.
Keywords:
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号