Title :
Adaptive DDoS Detector Design Using Fast Entropy Computation Method
Author :
No, Giseop ; Ra, Ilkyeun
Author_Institution :
Sch. of Comput. Sci. & Eng., Seoul Nat. Univ., Seoul, South Korea
fDate :
June 30 2011-July 2 2011
Abstract :
Recently, the threat of DDoS (Distributed Denial-of-Service) attacks is growing continuously and acquiring attacking tools via Internet is getting easy. One of the researches introduced a fast method to detect attacks using modified information entropy (so called Fast Entropy). Fast Entropy shows the significant reduce of computational time compared to conventional entropy computation while it maintains detection accuracy. However, Fast Entropy needs the manual threshold settings during detection process which is not realistic in real detection facility. We introduce adaptive detector with dynamic detection window size and adaptive threshold shifting using Fast Entropy, called AFEA (Adaptive DDoS attack detection using Fast Entropy Approach). Our adaptive DDoS detector successfully demonstrates that its performance of the DDoS detection can be enhanced by the best result of Fast Entropy detection scheme without manual threshold setting and system training while it maintains the same computational time of Fast Entropy detection scheme. In addition, we found that Dynamic AFEA can enhance detection level more than fixed (non-dynamic) one when it is equipped with Fast Entropy.
Keywords :
Internet; entropy; security of data; Internet; adaptive DDoS attack detection using fast entropy approach; adaptive threshold shifting; distributed denial-of-service attacks; dynamic detection window size; Accuracy; Computer crime; Detectors; Entropy; IP networks; Internet; Monitoring; DDoS; Dynamic Adaptive Detector; Entropy based approach; Fast Infromatin Entropy;
Conference_Titel :
Innovative Mobile and Internet Services in Ubiquitous Computing (IMIS), 2011 Fifth International Conference on
Conference_Location :
Seoul
Print_ISBN :
978-1-61284-733-7
Electronic_ISBN :
978-0-7695-4372-7
DOI :
10.1109/IMIS.2011.82