首页> 外文期刊>EURASIP journal on advances in signal processing >Detecting Pulsing Denial-of-Service Attacks with Nondeterministic Attack Intervals
【24h】

Detecting Pulsing Denial-of-Service Attacks with Nondeterministic Attack Intervals

机译:使用不确定的攻击间隔检测脉冲式拒绝服务攻击

获取原文
           

摘要

This paper addresses the important problem of detecting pulsing denial of service (PDoS) attacks which send a sequence of attack pulses to reduce TCP throughput. Unlike previous works which focused on a restricted form of attacks, we consider a very broad class of attacks. In particular, our attack model admits any attack interval between two adjacent pulses, whether deterministic or not. It also includes the traditional flooding-based attacks as a limiting case (i.e., zero attack interval). Our main contribution is Vanguard, a new anomaly-based detection scheme for this class of PDoS attacks. The Vanguard detection is based on three traffic anomalies induced by the attacks, and it detects them using a CUSUM algorithm. We have prototyped Vanguard and evaluated it on a testbed. The experiment results show that Vanguard is more effective than the previous methods that are based on other traffic anomalies (after a transformation using wavelet transform, Fourier transform, and autocorrelation) and detection algorithms (e.g., dynamic time warping).
机译:本文解决了检测脉冲拒绝服务(PDoS)攻击的重要问题,该攻击发送一系列攻击脉冲以降低TCP吞吐量。与以前的工作着眼于有限的攻击形式不同,我们认为攻击的类别非常广泛。特别是,我们的攻击模型允许两个相邻脉冲之间的任何攻击间隔,无论是否确定。它还包括传统的基于泛洪的攻击作为一种限制情况(即零攻击间隔)。我们的主要贡献是Vanguard,这是一种针对此类PDoS攻击的基于异常的新检测方案。 Vanguard检测基于攻击引起的三个流量异常,并使用CUSUM算法对其进行检测。我们已经为Vanguard制作了原型,并在测试平台上对其进行了评估。实验结果表明,Vanguard比基于其他流量异常(使用小波变换,傅立叶变换和自相关的变换)和检测算法(例如动态时间扭曲)的基于先前方法的方法更为有效。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号