首页> 外文会议>IASTED International Conference on Computational Intelligence >DOS ATTACK DETECTION USING SOURCE IP ADDRESS ENTROPY AND AVERAGE PACKET ARRIVAL TIME INTERVAL
【24h】

DOS ATTACK DETECTION USING SOURCE IP ADDRESS ENTROPY AND AVERAGE PACKET ARRIVAL TIME INTERVAL

机译:DOS攻击检测使用源IP地址熵和平均数据包到达时间间隔

获取原文

摘要

DoS attack is the threat to ICT(Information and commu-nications technology) society. There are many detection methods. But countermeasures have been become difficult according to complication of attacks. In conventional methods, the property of entropy is used to detect attacks. It enables to estimate increase and decrease of dispersion of header information values, like IP address, by comparing before and after entropy values in time series. In these methods, the detection rate with only one header information is low in accuracy. Therefore various kinds of header information are necessary for accurate detection. However, it takes a long time to distinguish DoS attacks and also the detection method becomes complicated. This paper proposes the detection method with only 2 header information, "Packet arrival time" and "Source IP address". The method can be used to detect DoS attacks with fewer number of header information than conventional methods. In addition, False Positive and False Negative are less than 2% and 0%, respectively. From these results, the method is not only simple but also accurate.
机译:DOS攻击是对ICT(信息和致新技术)社会的威胁。有许多检测方法。但根据攻击的并发症,对策已经变得困难。在传统方法中,熵的性质用于检测攻击。通过在时间序列中的熵值之前和之后,可以估计报头信息值,如IP地址的分散的增加和减少。在这些方法中,只有一个报头信息的检测速率精度低。因此,各种报头信息对于精确检测是必要的。但是,区分DOS攻击需要很长时间,并且检测方法变得复杂。本文提出了仅具有2个报头信息的检测方法,“分组到达时间”和“源IP地址”。该方法可用于检测与较少数量的报头信息的DOS攻击,而不是传统方法。此外,假阳性和假阴性分别小于2%和0%。从这些结果来看,该方法不仅简单而且准确。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号