• DocumentCode
    584799
  • Title

    An efficient detection of flooding attacks to Internet Threat Monitors (ITM) using entropy variations under low traffic

  • Author

    Prasad, K.M. ; Reddy, A.R.M. ; Rao, K.V.

  • Author_Institution
    Dept. of CSE, Sree Vidyanikethan Eng. Coll., Tirupati, India
  • fYear
    2012
  • fDate
    26-28 July 2012
  • Firstpage
    1
  • Lastpage
    11
  • Abstract
    The Internet Threat Monitoring (ITM),is a globally scoped Internet monitoring system whose goal is to measure, detect, characterize, and track threats such as distribute denial of service(DDoS) attacks and worms. To block the monitoring system in the internet the attackers are targeted the ITM system. In this paper we address flooding attack against ITM system in which the attacker attempt to exhaust the network and ITM´s resources, such as network bandwidth, computing power, or operating system data structures by sending the malicious traffic. We propose an information-theoretic frame work that models the flooding attacks using Botnet on ITM. Based on this model we generalize the flooding attacks and propose an effective attack detection and Traceback using Entropy by calculating the entropy variations between normal and attack traffic.
  • Keywords
    Internet; computer network security; data structures; telecommunication traffic; DDoS; ITM; Internet threat monitors; computing power; denial of service attacks; efficient detection; entropy variations; flooding attacks; low traffic; malicious traffic; network bandwidth; operating system data structures; Floods; IP networks; Servers; Botnet; DDoS; Entropy and Entropy variations; Flooding attack; Internet Threat Monitors (ITM);
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computing Communication & Networking Technologies (ICCCNT), 2012 Third International Conference on
  • Conference_Location
    Coimbatore
  • Type

    conf

  • DOI
    10.1109/ICCCNT.2012.6395959
  • Filename
    6395959