• DocumentCode
    2290941
  • Title

    Detecting distributed denial-of-service attacks by analyzing TCP SYN packets statistically

  • Author

    Ohsita, Yuichi ; Ata, Shingo ; Murata, Masayuki

  • Author_Institution
    Graduate Sch. of Inf. Sci. & Technol., Osaka Univ., Japan
  • Volume
    4
  • fYear
    2004
  • fDate
    29 Nov.-3 Dec. 2004
  • Firstpage
    2043
  • Abstract
    Distributed denial-of-service attacks on public servers have recently become more serious. More are SYN flood attacks, since the malicious attackers can easily exploit the TCP specification to generate traffic making public servers unavailable. To assure that network services will not be interrupted, we need faster and more accurate defense mechanisms against malicious traffic, especially SYN floods. One of the problems in detecting SYN flood traffic is that server nodes or firewalls cannot distinguish the SYN packets of normal TCP connections from those of SYN flood attack. Moreover, since the rate of normal network traffic may vary, we cannot use an explicit threshold of SYN arrival rates to detect SYN flood traffic. In this paper we introduce a mechanism for detecting SYN flood traffic more accurately by taking into consideration the the time variation of arrival traffic. We first investigate the statistics of the arrival rates of both normal TCP SYN packets and SYN flood attack packets. We then describe our new detection mechanism based on the statistics of SYN arrival rates. Our analytical results show that the arrival rate of normal TCP SYN packets can be modeled by a normal distribution and that our proposed mechanism can detect SYN flood traffic quickly and accurately regardless of time variance of the traffic.
  • Keywords
    Internet; computer crime; computer network management; normal distribution; telecommunication traffic; SYN flood attacks; TCP SYN packets; TCP specification; arrival rates; detection mechanism; distributed denial-of-service attacks; malicious traffic; normal distribution; public servers; Computer crime; Floods; Gaussian distribution; Information analysis; Information science; Network servers; Statistical distributions; Telecommunication traffic; Traffic control; Web and internet services;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Global Telecommunications Conference, 2004. GLOBECOM '04. IEEE
  • Print_ISBN
    0-7803-8794-5
  • Type

    conf

  • DOI
    10.1109/GLOCOM.2004.1378371
  • Filename
    1378371