DocumentCode
1831911
Title
Parametric Differences between a Real-world Distributed Denial-of-Service Attack and a Flash Event
Author
Bhatia, Sajal ; Mohay, George ; Tickle, Alan ; Ahmed, Ejaz
Author_Institution
Inf. Security Inst., Queensland Univ. of Technol., Brisbane, QLD, Australia
fYear
2011
fDate
22-26 Aug. 2011
Firstpage
210
Lastpage
217
Abstract
Distributed Denial-of-Service (DDoS) attacks continue to be one of the most pernicious threats to the delivery of services over the Internet. Not only are DDoS attacks present in many guises, they are also continuously evolving as new vulnerabilities are exploited. Hence accurate detection of these attacks still remains a challenging problem and a necessity for ensuring high-end network security. An intrinsic challenge in addressing this problem is to effectively distinguish these Denial-of-Service attacks from similar looking Flash Events (FEs) created by legitimate clients. A considerable overlap between the general characteristics of FEs and DDoS attacks makes it difficult to precisely separate these two classes of Internet activity. In this paper we propose parameters which can be used to explicitly distinguish FEs from DDoS attacks and analyse two real-world publicly available datasets to validate our proposal. Our analysis shows that even though FEs appear very similar to DDoS attacks, there are several subtle dissimilarities which can be exploited to separate these two classes of events.
Keywords
Internet; computer network security; Internet; distributed denial-of-service attack; flash event; general characteristics; network security; Ash; Computer crime; IP networks; Iron; Web servers; Botnet; Distributed Denial-of-service (DDoS); Flash Event; Network Security;
fLanguage
English
Publisher
ieee
Conference_Titel
Availability, Reliability and Security (ARES), 2011 Sixth International Conference on
Conference_Location
Vienna
Print_ISBN
978-1-4577-0979-1
Electronic_ISBN
978-0-7695-4485-4
Type
conf
DOI
10.1109/ARES.2011.39
Filename
6045965
Link To Document