首页> 外文期刊>Turkish Journal of Electrical Engineering and Computer Sciences >A generalized detection system to detect distributed denial of service attacks and flash events for information theory metrics
【24h】

A generalized detection system to detect distributed denial of service attacks and flash events for information theory metrics

机译:通用检测系统,用于检测分布式拒绝服务攻击和闪存事件,以获取信息论指标

获取原文
           

摘要

A generalized detection system to detect distributed denial of service attacks and flash events for information theory metrics Authors: SUNNY BEHAL, KRISHAN KUMAR, MONIKA SACHDEVA Abstract: Distributed denial of service (DDoS) attacks pose a severe threat to extensively used web-based services and applications. Many detection approaches have been proposed in the literature, but ensuring the security and availability of data, resources, and services to end users remains an ongoing research challenge. Nowadays, the traffic volume of legitimate users has also increased manifold. A flash event (FE) is a high-rate legitimate traffic situation wherein millions of legitimate users start accessing a particular network resource, such as a web server, simultaneously. The detection of DDoS attacks becomes more challenging when DDoS attacks are launched during behaviorally similar FEs. This research paper proposes a generalized detection system for metrics, based on information theory, capable of detecting different types of DDoS attacks and FEs. We used publically available MIT Lincoln, CAIDA, and FIFA datasets along with a synthetically generated DDoSTB dataset to validate the proposed detection algorithm in terms of various detection system evaluation metrics such as false positive rate, false negative rate, classification rate, and detection accuracy. Such a generalized detection system would be useful to researchers for validating and comparing various information theory metrics based solutions. Keywords: DDoS attacks, network security, information theory, flash event, entropy, divergence Full Text: PDF.
机译:一种通用检测系统,用于检测分布式拒绝服务攻击和Flash事件以获取信息论指标作者:SUNNY BEHAL,KRISHAN KUMAR,MONIKA SACHDEVA摘要:分布式拒绝服务(DDoS)攻击严重威胁着广泛使用的基于Web的服务和应用程序。文献中已经提出了许多检测方法,但是确保数据,资源和对最终用户的服务的安全性和可用性仍然是一项持续的研究挑战。如今,合法用户的流量也不断增加。刷新事件(FE)是一种高速合法流量情况,其中数百万合法用户开始同时访问特定的网络资源(例如Web服务器)。当在行为相似的FE中发起DDoS攻击时,DDoS攻击的检测变得更具挑战性。本文基于信息论提出了一种通用的度量检测系统,能够检测不同类型的DDoS攻击和FE。我们使用公开可用的MIT Lincoln,CAIDA和FIFA数据集以及综合生成的DDoSTB数据集,根据各种检测系统评估指标(例如误报率,误报率,分类率和检测精度)来验证提出的检测算法。这样的通用检测系统对于研究人员用于验证和比较各种基于信息理论度量的解决方案将是有用的。关键字:DDoS攻击,网络安全,信息论,闪存事件,熵,散度全文:PDF。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号