首页> 外文期刊>Journal of Intelligent Manufacturing >Deciding optimal entropic thresholds to calibrate the detection mechanism for variable rate DDoS attacks in ISP domain: honeypot based approach
【24h】

Deciding optimal entropic thresholds to calibrate the detection mechanism for variable rate DDoS attacks in ISP domain: honeypot based approach

机译:确定最佳熵阈值以校准ISP域中可变速率DDoS攻击的检测机制:基于蜜罐的方法

获取原文
获取原文并翻译 | 示例
           

摘要

High bandwidth DDoS attacks consume more resources and have direct impact at ISP level in contrast to low rate DDoS attacks which lead to graceful degradation of network and are mostly undetectable. Although an array of detection schemes have been proposed, current requirement is a real time DDoS detection mechanism that adapts itself to varying network conditions to give minimum false alarms. DDoS attacks that disturb the distribution of traffic features in ISP domain are reflected by entropic variations on in stream samples. We propose honeypot detection for attack traffic having statistically similar distribution features as legitimate traffic. Next we propose to calibrate the detection mechanism for minimum false alarm rate by varying tolerance factor in real time. Simulations are carried out in ns-2 at different attack strengths. We also report our experimental results over MIT Lincoln lab dataset and its subset KDD 99 dataset. Results show that the proposed approach is comparable to previously reported approaches with an advantage of variable rate attack detection with minimum false positives and negatives.
机译:高带宽DDoS攻击会消耗更多资源,并直接影响ISP级别,而低速率DDoS攻击会导致网络正常降级,并且几乎无法检测到。尽管已经提出了一系列检测方案,但是当前的需求是一种实时DDoS检测机制,该机制可以使其自身适应变化的网络条件以提供最少的误报。流样本中的熵变化反映了干扰ISP域中流量功能分布的DDoS攻击。我们提出针对攻击流量的蜜罐检测,该流量在统计上与合法流量具有相似的分布特征。接下来,我们建议通过实时改变容限因子来校准最小误报率的检测机制。在ns-2中以不同的攻击强度进行仿真。我们还报告了MIT林肯实验室数据集及其子集KDD 99数据集的实验结果。结果表明,所提出的方法可与以前报告的方法相媲美,并且具有可变速率攻击检测的优势,且误报率和误报率均最小。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号