DocumentCode
2445844
Title
Efficient detection of DDoS attacks with important attributes
Author
Wang, Wei ; Gombault, Sylvain
Author_Institution
Dream Team, IRISA, Rennes
fYear
2008
fDate
28-30 Oct. 2008
Firstpage
61
Lastpage
67
Abstract
DDoS attacks are major threats in current computer networks. However, DDoS attacks are difficult to be quickly detected. In this paper, we introduce a system that only extracts several important attributes from network traffic for DDoS attack detection in real computer networks. We collect a large set of DDoS attack traffic by implementing various DDoS attacks as well as normal data during normal usage. Information Gain and Chi-square methods are used to rank the importance of 41 attributes extracted from the network traffic with our programs. Bayesian networks as well as C4.5 are then employed to detect attacks as well as to determine what size of attributes is appropriate for fast detection. Empirical results show that only using the most important 9 attributes, the detection accuracy remains the same or even has some improvements compared with that of using all the 41 attributes based on Bayesian Networks and C4.5 methods. Only using several attributes also improves the efficiency in terms of attributes constructing, models training as well as intrusion detection.
Keywords
belief networks; security of data; Bayesian networks; DDoS attacks; attribute selection;; distributed denial-of-service attack; intrusion detection system; Bayesian methods; Computer crime; Computer networks; Computer security; Data mining; IP networks; Intrusion detection; Multimedia systems; Statistics; Telecommunication traffic; Bayesian networks; C4.5; DDoS attack detection; Intrusion detection system; attribute selection;
fLanguage
English
Publisher
ieee
Conference_Titel
Risks and Security of Internet and Systems, 2008. CRiSIS '08. Third International Conference on
Conference_Location
Tozeur
Print_ISBN
978-1-4244-3309-4
Type
conf
DOI
10.1109/CRISIS.2008.4757464
Filename
4757464
Link To Document