首页> 外文会议>Proceedings of the 34th IASTED International Conference on Modelling, Identification and Control >DOS ATTACK DETECTION USING SOURCE IP ADDRESS ENTROPY AND AVERAGE PACKET ARRIVAL TIME INTERVAL
【24h】

DOS ATTACK DETECTION USING SOURCE IP ADDRESS ENTROPY AND AVERAGE PACKET ARRIVAL TIME INTERVAL

机译:使用源IP地址熵和平均数据包到达时间间隔进行DOS攻击检测

获取原文
获取原文并翻译 | 示例

摘要

DoS attack is the threat to ICT(Information and communications technology) society. There are many detection methods. But countermeasures have been become difficult according to complication of attacks. In conventional methods, the property of entropy is used to detect attacks. It enables to estimate increase and decrease of dispersion of header information values, like IP address, by comparing before and after entropy values in time series. In these methods, the detection rate with only one header information is low in accuracy. Therefore various kinds of header information are necessary for accurate detection. However, it takes a long time to distinguish DoS attacks and also the detection method becomes complicated. This paper proposes the detection method with only 2 header information, "Packet arrival time" and "Source IP address". The method can be used to detect DoS attacks with fewer number of header information than conventional methods. In addition, False Positive and False Negative are less than 2% and 0%, respectively. From these results, the method is not only simple but also accurate.
机译:DoS攻击是对ICT(信息和通信技术)社会的威胁。有很多检测方法。但是,由于攻击的复杂性,对策变得困难。在常规方法中,熵的性质用于检测攻击。通过比较时间序列中的熵值之前和之后,它可以估计报头信息值(如IP地址)的离散程度的增加和减少。在这些方法中,仅具有一个报头信息的检测率精度低。因此,各种标题信息对于精确检测是必要的。但是,区分DoS攻击需要花费很长时间,并且检测方法也变得复杂。本文提出了一种仅包含两个报头信息的检测方法:“数据包到达时间”和“源IP地址”。与常规方法相比,该方法可用于以更少的标头信息检测DoS攻击。此外,误报率和误报率分别小于2%和0%。从这些结果来看,该方法不仅简单而且准确。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号