首页> 外文会议>Asia Joint Conference on Information Security >A Simple Detection Method for DoS Attacks Based on IP Packets Entropy Values
【24h】

A Simple Detection Method for DoS Attacks Based on IP Packets Entropy Values

机译:基于IP数据包熵值的DoS攻击简单检测方法

获取原文

摘要

DoS attack is the threat to ICT (Information and communications technology) society. There are many existed detection methods, but countermeasures has been become difficult according to complication of attacks. In conventional methods, entropy-based methods detect attacks using the property of entropy that it enables to estimate increase and decrease of dispersion of header information values, like IP address, by comparing before and after entropy values in time series. In this method, the detection with only one header information is low accuracy, so some or many header information is necessary for accurate detection. Therefore, time for calculating their entropy is needed and the detection method becomes complicated. In this way, requiring some or many header information is the cause of the such problem. So in this paper, we propose the detection method with only 2 header information that is fewer than conventional methods: "packet arrival time" and "source IP address". First, we analyzed two datasets, calculated entropy values of header information. Second, we extracted common features of DoS attacks between two datasets, proposed the detection method detect that feature. As a result, the proposed method with only 2 header information became simpler than conventional methods. And we was able to distinguish the attack time from the non-attack time clearly.
机译:DoS攻击是对ICT(信息和通信技术)社会的威胁。现有的检测方法很多,但是随着攻击的复杂化,对策变得困难。在常规方法中,基于熵的方法使用熵的属性来检测攻击,该属性使得能够通过比较时间序列中的熵值前后的值来估计报头信息值(如IP地址)的离散程度的增加和减少。在该方法中,仅具有一个报头信息的检测的准确性较低,因此对于准确检测而言,一些或多个报头信息是必需的。因此,需要用于计算它们的熵的时间,并且检测方法变得复杂。以这种方式,需要一些或许多头信息是这种问题的原因。因此,在本文中,我们提出了一种仅具有2个标头信息的检测方法,该方法比常规方法要少:“数据包到达时间”和“源IP地址”。首先,我们分析了两个数据集,计算了标头信息的熵值。其次,我们提取了两个数据集之间的DoS攻击的共同特征,提出了检测该特征的检测方法。结果,所提出的仅具有2个报头信息的方法变得比传统方法更简单。而且我们能够清楚地将攻击时间与非攻击时间区分开。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号