• DocumentCode
    2299795
  • Title

    Discriminating DDoS Flows from Flash Crowds Using Information Distance

  • Author

    Yu, Shui ; Thapngam, Theerasak ; Liu, Jianwen ; Wei, Su ; Zhou, Wanlei

  • Author_Institution
    Deakin Univ., Burwood, VIC, Australia
  • fYear
    2009
  • fDate
    19-21 Oct. 2009
  • Firstpage
    351
  • Lastpage
    356
  • Abstract
    Discriminating DDoS flooding attacks from flash crowds poses a tough challenge for the network security community. Because of the vulnerability of the original design of the Internet, attackers can easily mimic the patterns of legitimate network traffic to fly under the radar. The existing fingerprint or feature based algorithms are incapable to detect new attack strategies. In this paper, we aim to differentiate DDoS attack flows from flash crowds. We are motivated by the following fact: the attack flows are generated by the same prebuilt program (attack tools), however, flash crowds come from randomly distributed users all over the Internet. Therefore, the flow similarity among DDoS attack flows is much stronger than that among flash crowds. We employ abstract distance metrics, the Jeffrey distance, the Sibson distance, and the Hellinger distance to measure the similarity among flows to achieve our goal. We compared the three metrics and found that the Sibson distance is the most suitable one for our purpose. We apply our algorithm to the real datasets and the results indicate that the proposed algorithm can differentiate them with an accuracy around 65%.
  • Keywords
    Internet; security of data; Hellinger distance; Internet; Jeffrey distance; Sibson distance; abstract distance metrics; discriminating DDoS flows; feature based algorithms; fingerprint algorithms; flash crowds; flooding attacks; flow similarity; information distance; legitimate network traffic; network security; Computer crime; Computer hacking; Detectors; Entropy; Fingerprint recognition; Frequency domain analysis; Information security; Internet; Radar detection; Telecommunication traffic; DDoS Attack; Distance; Measurement;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Network and System Security, 2009. NSS '09. Third International Conference on
  • Conference_Location
    Gold Coast, QLD
  • Print_ISBN
    978-1-4244-5087-9
  • Electronic_ISBN
    978-0-7695-3838-9
  • Type

    conf

  • DOI
    10.1109/NSS.2009.29
  • Filename
    5319279