• DocumentCode
    1891856
  • Title

    Detection of low-rate attacks in computer networks

  • Author

    Thatte, Gautam ; Mitra, Urbashi ; Heidemann, John

  • Author_Institution
    Ming Hsieh Dept. of Electr. Eng., Univ. of Southern California, Los Angeles, CA
  • fYear
    2008
  • fDate
    13-18 April 2008
  • Firstpage
    1
  • Lastpage
    6
  • Abstract
    This paper develops two parametric methods to detect low-rate denial-of-service attacks and other similar near-periodic traffic, without the need for flow separation. The first method, the periodic attack detector, is based on a previous approach that exploits the near-periodic nature of attack traffic in aggregate traffic by modeling the peak frequency in the traffic spectrum. The new method adopts simple statistical models for attack and background traffic in the time-domain. Both approaches use sequential probability ratio tests (SPRTs), allowing control over false alarm rate while examining the trade-off between detection time and attack strength. We evaluate these methods with real and synthetic traces, observing that the new Poisson- based scheme uniformly detects attacks more rapidly, often in less than 200 ms, and with lower complexity than the periodic attack detector. Current entropy-based detection methods provide an equivalent time to detection but require flow-separation since they utilize source/destination IP addresses. We evaluate sensitivity to attack strength (compared to the rate of background traffic) with synthetic traces, finding that the new approach can detect attacks that represent only 10% of the total traffic bitrate in fractions of a second.
  • Keywords
    IP networks; entropy; probability; security of data; stochastic processes; telecommunication security; telecommunication traffic; IP addresses; Poisson-based scheme; computer networks; entropy-based detection methods; low-rate denial-of-service attack detection; near-periodic traffic; parametric methods; peak frequency modeling; periodic attack detector; sequential probability ratio tests; statistical models; traffic spectrum; Aggregates; Communication system traffic control; Computer crime; Computer networks; Detectors; Frequency; Probability; Telecommunication traffic; Time domain analysis; Traffic control;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    INFOCOM Workshops 2008, IEEE
  • Conference_Location
    Phoenix, AZ
  • Print_ISBN
    978-1-4244-2219-7
  • Type

    conf

  • DOI
    10.1109/INFOCOM.2008.4544638
  • Filename
    4544638