【24h】

STDC: A SDN-Oriented Two-Stage DDoS Detection and Defence System Based on Clustering

机译:STDC:基于集群的面向SDN的两阶段DDoS检测与防御系统

获取原文
获取原文并翻译 | 示例

摘要

DDoS has now become the most severe security problem of the Internet. Without in time report, DDoS attack can knock down the victim in no time by exhausting the victim's computing and communicating resources. In this paper we propose STDC-a DDoS defense system. STDC is a two-stage system based on clustering. In the first stage STDC leverage the benefit of SDN and NFV to apply flow-based detection method. STDC use the flow information gathered to do clustering. Since we use cluster analysis as the basic detection algorithm, STDC can separate the DDoS attacks from the legitimate flush crowd easily. In the second stage, we extract attack traffic pattern from the clustering result of the first stage to make blocking rules and use the structure of SDN to quickly dispatch them to achieve effictive and efficient DDoS mitigation. We test STDC using public DDoS dataset and the traffic captured through the gateway. Both of the experiments achieve good detection percision and high filtering ratio.
机译:DDoS现在已成为Internet上最严重的安全问题。如果没有及时报告,DDoS攻击将通过耗尽受害者的计算和通信资源来立即击倒受害者。在本文中,我们提出了STDC-a DDoS防御系统。 STDC是基于集群的两阶段系统。在第一阶段,STDC利用SDN和NFV的优势来应用基于流的检测方法。 STDC使用收集的流信息进行聚类。由于我们使用聚类分析作为基本的检测算法,因此STDC可以轻松将DDoS攻击与合法的正常人群隔离开。在第二阶段,我们从第一阶段的聚类结果中提取攻击流量模式,以制定阻塞规则,并使用SDN的结构快速将其分发,以实现高效有效的DDoS缓解。我们使用公共DDoS数据集和通过网关捕获的流量来测试STDC。这两个实验均实现了良好的检测精度和较高的过滤率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号