MSABMS-based approach of detecting LDoS attack
نویسندگان
چکیده
Low-rate Denial of Service (LDoS) attacks exploit the deficiencies of the minimum RTO of TCP to send out attack packets in short-duration periodic pulses with low average volume traffic in order to throttle TCP throughput. It is hard to detect an LDoS attack by most available detection schemes, which are triggered by high-rate traffic based on time average statistics. In this paper, the method of Multiple Sampling Averaging Based on Missing Sampling (MSABMS) is used to detect LDoS attacks based on the model of small signal for the first time. In the proposed approach, statistics on the packets are taken within 30 s with the sampling interval of 10 ms (3000 sampling points in total), and the statistical results are compared with a threshold for identifying the LDoS attacks. Furthermore, an eigenvalueestimating matrix is established to estimate the attack period after the detection of LDoS attacks. Simulation results in NS-2 environment show that the proposed approach can be used to detect the LDoS attack effectively. a 2012 Published by Elsevier Ltd.
منابع مشابه
Correlation-based Detection of LDoS Attack
s—Low-rate Denial of Service (LDoS) attack and TCP flows are simulated in the time and frequency domain for the purpose of analyzing their signatures and extracting period T and duration L of LDoS attack, which are two correlative parameters used in the proposed detecting approach. In the correlation operation, the reference signal is the simulated traffic of LDoS attack, which are built based ...
متن کاملSoftware based Low Rate DoS Attack Detection Mechanism
Existing DoS attack detection tools are unable to detect Low rate DoS (LDoS) attacks. Many researchers have proposed mechanisms to detect LdoS attack. But they require modifications to the existing infrastructure or protocols which is not practical. There should be a lightweight mechanism which could be integrated with existing Intrusion Detection Systems. This paper proposes a lightweight soft...
متن کاملResearch on the Aggregation and Synchronization of LDDoS Attack Based On Euclidean Distance
Flow aggregation or time synchronization ensures low-rate denial of service (LDoS) attack flows form an ideal rectangular pulse at the victim to maximize attack efficiency. The differences of end-to-end delay between each host are critical for aggregation or synchronization. A new approach based on Euclidean distance is proposed to avoid the complexity of direct measuring internet end-to-end de...
متن کاملA New Detection Method based on AEWMA Algorithm for LDoS attacks
The Low-rate Denial of Service (LDoS) attack is a new type of DoS (Denial of Service) attack, which produces the similar harmful effect as the DoS attack. It is more difficult for existing DoS detection methods to detect the LDoS attacks because of their distinct characteristics, at the same time the accuracy of the current detection methods for the LDoS attacks is relatively low. However, when...
متن کاملShrew Attack Prevention in RED Queue with Partial Flow Analysis
Shrew Attacks or Low Rate Denial of Service(LDoS) Attacks are initiated by sending large amount of packets for very short span of time such that the packet sending rate crosses the link capacity resulting in network congestion. Compared to Denial of Service (DoS) Attack, LDoS attack is very difficult to be detected because, the attacker can maintain low average packet sending rate while executi...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
- Computers & Security
دوره 31 شماره
صفحات -
تاریخ انتشار 2012