• DocumentCode
    128021
  • Title

    Investigating the utility of S-transform for detecting Denial-of-Service and probe attacks

  • Author

    Pukkawanna, Sirikarn ; Hazeyama, Hiroaki ; Kadobayashi, Youki ; Yamaguchi, Satarou

  • Author_Institution
    Grad. Sch. of Inf. Sci., Nara Inst. of Sci. & Technol., Ikoma, Japan
  • fYear
    2014
  • fDate
    10-12 Feb. 2014
  • Firstpage
    282
  • Lastpage
    287
  • Abstract
    Denial-of-Service (DoS) and probe attacks are growing more modern and sophisticated in order to evade detection by Intrusion Detection Systems (IDSs) and to increase the potent threat to the availability of network services. Detecting these attacks is quite tough for network operators using misuse-based IDSs because they need to see through attackers and upgrade their IDSs by adding new accurate attack signatures. In this paper, we proposed a novel signal and image processing-based method for detecting network probe and DoS attacks in which prior knowledge of attacks is not required. The method uses a time-frequency representation technique called S-transform, which is an extension of Wavelet Transform, to reveal abnormal frequency components caused by attacks in a traffic signal (e.g., a time-series of the number of packets). Firstly, S-Transform converts the traffic signal to a two-dimensional image which describes time-frequency behavior of the traffic signal. The frequencies that behave abnormally are discovered as abnormal regions in the image. Secondly, Otsu´s method is used to detect the abnormal regions and identify time that attacks occur. We evaluated the effectiveness of the proposed method with several network probe and DoS attacks such as port scans, packet flooding attacks, and a low-intensity DoS attack. The results clearly indicated that the method is effective for detecting the probe and DoS attack streams which were generated to real-world Internet.
  • Keywords
    Internet; computer network security; telecommunication traffic; time-frequency analysis; wavelet transforms; DoS attacks; IDS; Internet; Otsu method; S-transform; accurate attack signatures; denial-of-service detection; frequency components; image processing method; intrusion detection systems; probe attacks; signal processing method; time-frequency representation technique; traffic signal; two-dimensional image; wavelet transform; Computer crime; Internet; Ports (Computers); Probes; Time-frequency analysis; Wavelet transforms;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Networking (ICOIN), 2014 International Conference on
  • Conference_Location
    Phuket
  • Type

    conf

  • DOI
    10.1109/ICOIN.2014.6799482
  • Filename
    6799482