• DocumentCode
    1431930
  • Title

    Low-Rate DDoS Attacks Detection and Traceback by Using New Information Metrics

  • Author

    Xiang, Yang ; Li, Ke ; Zhou, Wanlei

  • Author_Institution
    Sch. of Inf. Technol., Deakin Univ., Burwood, VIC, Australia
  • Volume
    6
  • Issue
    2
  • fYear
    2011
  • fDate
    6/1/2011 12:00:00 AM
  • Firstpage
    426
  • Lastpage
    437
  • Abstract
    A low-rate distributed denial of service (DDoS) attack has significant ability of concealing its traffic because it is very much like normal traffic. It has the capacity to elude the current anomaly-based detection schemes. An information metric can quantify the differences of network traffic with various probability distributions. In this paper, we innovatively propose using two new information metrics such as the generalized entropy metric and the information distance metric to detect low-rate DDoS attacks by measuring the difference between legitimate traffic and attack traffic. The proposed generalized entropy metric can detect attacks several hops earlier (three hops earlier while the order α = 10 ) than the traditional Shannon metric. The proposed information distance metric outperforms (six hops earlier while the order α = 10) the popular Kullback-Leibler divergence approach as it can clearly enlarge the adjudication distance and then obtain the optimal detection sensitivity. The experimental results show that the proposed information metrics can effectively detect low-rate DDoS attacks and clearly reduce the false positive rate. Furthermore, the proposed IP traceback algorithm can find all attacks as well as attackers from their own local area networks (LANs) and discard attack traffic.
  • Keywords
    entropy; security of data; DDoS attack detection; Kullback Leibler divergence; attack traffic; distributed denial of service; entropy metric; information distance metric; information metric; legitimate traffic; local area network; network traffic; optimal detection sensitivity; probability distribution; Collaboration; Computer crime; Entropy; IP networks; Information entropy; Measurement; Probability distribution; Attack detection; IP traceback; information metrics; low-rate distributed denial of service (DDoS) attack;
  • fLanguage
    English
  • Journal_Title
    Information Forensics and Security, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1556-6013
  • Type

    jour

  • DOI
    10.1109/TIFS.2011.2107320
  • Filename
    5696753