DocumentCode :
2576266
Title :
Real time detection and classification of DDoS attacks using enhanced SVM with string kernels
Author :
Ramamoorthi, A. ; Subbulakshmi, T. ; Shalinie, S. Mercy
Author_Institution :
Dept. of Comput. Sci. & Eng., Thiagarajar Coll. of Eng., Madurai, India
fYear :
2011
fDate :
3-5 June 2011
Firstpage :
91
Lastpage :
96
Abstract :
Distributed Denial of Service (DDoS) attack is a continuous critical threat to the internet. Application layer DDoS Attack is derived from the lower layers. Application layer based DDoS attacks use legitimate HTTP requests after establishment of TCP three way hand shaking and overwhelms the victim resources, such as sockets, CPU, memory, disk, database bandwidth. Network layer based DDoS attacks sends the SYN, UDP and ICMP requests to the server and exhausts the bandwidth. Normal profile is created from user´s access behavior attributes which is the base line to differentiate DDoS attacks from flash crowd. An anomaly detection mechanism is proposed in this paper to detect DDoS attacks using Enhanced Support Vector Machine (ESVM) with string kernels. Normal user access behavior attributes is used as training samples for ESVM, which produces the model file. Data collected during normal and attack is used as test samples for ESVM. Application and Network layer DDoS attacks are classified with classification accuracy of 99% with ESVM.
Keywords :
Internet; pattern classification; security of data; support vector machines; HTTP requests; Internet; SVM; TCP three way hand shaking; anomaly detection mechanism; application layer based DDoS attacks; distributed denial of service attack; enhanced support vector machine; network layer based DDoS attacks; real time detection; string kernels; Computer crime; Floods; IP networks; Kernel; Servers; Support vector machines; Training; Anomaly detection; DDoS; Enhanced Support Vector Machine (ESVM); Intrusion detection; String kernels;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Recent Trends in Information Technology (ICRTIT), 2011 International Conference on
Conference_Location :
Chennai, Tamil Nadu
Print_ISBN :
978-1-4577-0588-5
Type :
conf
DOI :
10.1109/ICRTIT.2011.5972281
Filename :
5972281
Link To Document :
بازگشت