首页> 外文会议>IEEE International Conference on Cognitive Informatics Cognitive Computing >A chaotic measure for cognitive machine classification of distributed denial of service attacks
【24h】

A chaotic measure for cognitive machine classification of distributed denial of service attacks

机译:分布式拒绝服务攻击的认知机器分类混沌措施

获取原文

摘要

Today's evolving cyber security threats demand new, modern, and cognitive computing approaches to network security systems. In the early years of the Internet, a simple packet inspection firewall was adequate to stop the then-contemporary attacks, such as Denial of Service (DoS), ports scans, and phishing. Since then, DoS has evolved to include Distributed Denial of Service (DDoS) attacks, especially against the Domain Name Service (DNS). DNS based DDoS amplification attacks cannot be stopped easily by traditional signature based detection mechanisms because the attack packets contain authentic data, and signature based detection systems look for specific attack-byte patterns. This paper proposes a chaos based complexity measure and a cognitive machine classification algorithm to detect DNS DDoS amplification attacks. In particular, this paper computes the Lyapunov exponent to measure the complexity of a flow of packets, and classifies the traffic as either normal or anomalous, based on the magnitude of the computed exponent. Preliminary results show the proposed chaotic measure achieved a detection (classification) accuracy of about 66%, which is greater than that reported in the literature. This approach is capable of not only detecting offline threats, but has the potential of being applied over live traffic flows using DNS filters.
机译:今天的网络安全系统需求新的网络安全威胁需求新的,现代和认知的计算方法。在互联网的初期,一个简单的数据包检查防火墙足以停止停止当时的攻击,例如拒绝服务(DOS),端口扫描和网络钓鱼。从那时起,DOS已经发展为包括分布式拒绝服务(DDOS)攻击,尤其是违反域名服务(DNS)。基于DNS的DDOS放大攻击不能通过传统的基于签名的检测机制停止,因为攻击数据包包含真实的数据,并且基于签名的检测系统查找特定的攻击字节模式。本文提出了一种基于混沌的复杂度和认知机分类算法来检测DNS DDOS扩增攻击。特别是,本文计算Lyapunov指数以测量数据包流的复杂性,并基于计算指数的幅度对正常或异常的流量进行分类。初步结果表明,拟议的混沌措施达到了约66%的检测(分类)精度,其大于文献中报道的约66%。这种方法不仅能够检测到脱机威胁,而且还具有使用DNS过滤器应用于实时流量流的潜力。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号