DocumentCode
2924004
Title
Lightweight Detection of DoS Attacks
Author
Pukkawanna, Sirikarn ; Visoottiviseth, Vasaka ; Pongpaibool, Panita
Author_Institution
Mahidol Univ., Bangkok
fYear
2007
fDate
19-21 Nov. 2007
Firstpage
77
Lastpage
82
Abstract
Denial of service (DoS) attacks have continued to evolve and impact availability of the Internet infrastructure. Many researchers in the field of network security and system survivability have been developing mechanisms to detect DoS attacks. By doing so they hope to maximize accurate detections (true-positive) and minimize non-justified detections (false-positive). This research proposes a lightweight method to identify DoS attacks by analyzing host behaviors. Our method is based on the concept of BLINd Classification or BLINC: no access to packet payload, no knowledge of port numbers, and no additional information other than what current flow collectors provide. Rather than using pre-defined signatures or rules as in typical Intrusion Detection Systems, BLINC maps flows into graphlets of each attack pattern. In this work we create three types of graphlets for the following DoS attack patterns: SYN flood, ICMP flood, and host scan. Results show that our method can identify all occurrences and all hosts associated with attack activities, with a low percentage of false positive.
Keywords
Internet; computer network reliability; telecommunication security; DoS attack; Internet; denial of service; lightweight detection; network security; system survivability; Availability; Bandwidth; Computer crime; Computer science; Floods; Inspection; Intrusion detection; Payloads; Telecommunication traffic; Web and internet services;
fLanguage
English
Publisher
ieee
Conference_Titel
Networks, 2007. ICON 2007. 15th IEEE International Conference on
Conference_Location
Adelaide, SA
ISSN
1556-6463
Print_ISBN
978-1-4244-1230-3
Electronic_ISBN
1556-6463
Type
conf
DOI
10.1109/ICON.2007.4444065
Filename
4444065
Link To Document