• DocumentCode
    1831911
  • Title

    Parametric Differences between a Real-world Distributed Denial-of-Service Attack and a Flash Event

  • Author

    Bhatia, Sajal ; Mohay, George ; Tickle, Alan ; Ahmed, Ejaz

  • Author_Institution
    Inf. Security Inst., Queensland Univ. of Technol., Brisbane, QLD, Australia
  • fYear
    2011
  • fDate
    22-26 Aug. 2011
  • Firstpage
    210
  • Lastpage
    217
  • Abstract
    Distributed Denial-of-Service (DDoS) attacks continue to be one of the most pernicious threats to the delivery of services over the Internet. Not only are DDoS attacks present in many guises, they are also continuously evolving as new vulnerabilities are exploited. Hence accurate detection of these attacks still remains a challenging problem and a necessity for ensuring high-end network security. An intrinsic challenge in addressing this problem is to effectively distinguish these Denial-of-Service attacks from similar looking Flash Events (FEs) created by legitimate clients. A considerable overlap between the general characteristics of FEs and DDoS attacks makes it difficult to precisely separate these two classes of Internet activity. In this paper we propose parameters which can be used to explicitly distinguish FEs from DDoS attacks and analyse two real-world publicly available datasets to validate our proposal. Our analysis shows that even though FEs appear very similar to DDoS attacks, there are several subtle dissimilarities which can be exploited to separate these two classes of events.
  • Keywords
    Internet; computer network security; Internet; distributed denial-of-service attack; flash event; general characteristics; network security; Ash; Computer crime; IP networks; Iron; Web servers; Botnet; Distributed Denial-of-service (DDoS); Flash Event; Network Security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Availability, Reliability and Security (ARES), 2011 Sixth International Conference on
  • Conference_Location
    Vienna
  • Print_ISBN
    978-1-4577-0979-1
  • Electronic_ISBN
    978-0-7695-4485-4
  • Type

    conf

  • DOI
    10.1109/ARES.2011.39
  • Filename
    6045965