• DocumentCode
    2784245
  • Title

    DDoS attack detection and wavelets

  • Author

    Li, Lan ; Lee, Gyungho

  • Author_Institution
    Dept. of Electr. & Comput. Eng., Illinois Univ., Chicago, IL, USA
  • fYear
    2003
  • fDate
    20-22 Oct. 2003
  • Firstpage
    421
  • Lastpage
    427
  • Abstract
    This paper presents a systematic method for DDoS attack detection. DDoS attack can be considered system anomaly or misuse from which abnormal behavior is imposed on network traffic. Attack detection can be performed via abnormal behavior identification. Network traffic characterization with behavior modeling could be a good guidance of attack detection. Aggregated traffic has been found to be strong bursty across a wide range of time scales. Wavelet analysis is able to capture complex temporal correlation across multiple time scales with very low computational complexity. We utilize energy distribution based on wavelet analysis to detect DDoS attack traffic. Energy distribution over time would have limited variation if the traffic keeps its behavior over time (i.e. attack-free situation); while an introduction of attack traffic in the network would elicit significant energy distribution deviation in short time period. Our experimental results with typical Internet traffic trace show that energy distribution variance changes markedly causing a "spike" when traffic behaviors affected by DDoS attack In contrast, normal traffic exhibits a remarkably stationary energy distribution. In addition, this spike in energy distribution variance can be captured in early stage of attack, for ahead of congestion build-up, making it an effective attack detection.
  • Keywords
    Internet; telecommunication congestion control; telecommunication traffic; DDoS attack detection; Internet traffic; abnormal behavior identification; behavior modeling; complex temporal correlation; computational complexity; congestion build-up; wavelet analysis based energy distribution; Computational complexity; Computer crime; Energy capture; Filtering; IP networks; Power generation economics; Telecommunication traffic; Traffic control; Wavelet analysis; Web and internet services;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Communications and Networks, 2003. ICCCN 2003. Proceedings. The 12th International Conference on
  • ISSN
    1095-2055
  • Print_ISBN
    0-7803-7945-4
  • Type

    conf

  • DOI
    10.1109/ICCCN.2003.1284203
  • Filename
    1284203