DocumentCode :
2894485
Title :
Classifying DDoS Attacks by Hierarchical Clustering Based on Similarity
Author :
Kang, Jian ; Zhang, Yuan ; Ju, Jiu-bin
Author_Institution :
Dept. of Comput. Sci., Jilin Univ., Changchun
fYear :
2006
fDate :
13-16 Aug. 2006
Firstpage :
2712
Lastpage :
2717
Abstract :
With the researching for detection and defense against distributed denial of service (DDoS) attacks, researchers constantly advanced network security systems, and attackers in turn improve their tools to survive from new security systems. Both of the variety and sophistication of DDoS attack tools are growing rapidly. Therefore, an abstract, formalized description and taxonomy is needed to identify and classify existing attack tools and their late editions. Besides, the taxonomy should be scalable to deal with new attacks. This paper proposes a novel and abstract method for describing DDoS attacks with characteristic tree, three-tuple, and introduces an original, formalized taxonomy based on similarity and hierarchical clustering method. Through classifying 12 real DDoS attack tools, the taxonomy is evaluated. The results show that to complicated attack samples, this taxonomy can classify them accurately. In addition, it is important for developing realistic models of DDoS simulation and for performing attacks detection and analysis as a plug-in. It can also be packaged as an automated tool to aid in rapid response to DDoS attacks
Keywords :
Internet; pattern classification; pattern clustering; telecommunication security; DDoS attack classification; Internet; distributed denial of service attack tool; network security system; similarity based hierarchical clustering; Analytical models; Binary codes; Clustering methods; Computer crime; Computer science; Computer security; Cybernetics; Electronic mail; Encoding; Machine learning; Packaging; Performance analysis; Taxonomy; DDoS attack; Hierarchical Clustering; formalized taxonomy; similarity;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Machine Learning and Cybernetics, 2006 International Conference on
Conference_Location :
Dalian, China
Print_ISBN :
1-4244-0061-9
Type :
conf
DOI :
10.1109/ICMLC.2006.258931
Filename :
4028522
Link To Document :
بازگشت