Title :
An efficient detection of flooding attacks to Internet Threat Monitors (ITM) using entropy variations under low traffic
Author :
Prasad, K.M. ; Reddy, A.R.M. ; Rao, K.V.
Author_Institution :
Dept. of CSE, Sree Vidyanikethan Eng. Coll., Tirupati, India
Abstract :
The Internet Threat Monitoring (ITM),is a globally scoped Internet monitoring system whose goal is to measure, detect, characterize, and track threats such as distribute denial of service(DDoS) attacks and worms. To block the monitoring system in the internet the attackers are targeted the ITM system. In this paper we address flooding attack against ITM system in which the attacker attempt to exhaust the network and ITM´s resources, such as network bandwidth, computing power, or operating system data structures by sending the malicious traffic. We propose an information-theoretic frame work that models the flooding attacks using Botnet on ITM. Based on this model we generalize the flooding attacks and propose an effective attack detection and Traceback using Entropy by calculating the entropy variations between normal and attack traffic.
Keywords :
Internet; computer network security; data structures; telecommunication traffic; DDoS; ITM; Internet threat monitors; computing power; denial of service attacks; efficient detection; entropy variations; flooding attacks; low traffic; malicious traffic; network bandwidth; operating system data structures; Floods; IP networks; Servers; Botnet; DDoS; Entropy and Entropy variations; Flooding attack; Internet Threat Monitors (ITM);
Conference_Titel :
Computing Communication & Networking Technologies (ICCCNT), 2012 Third International Conference on
Conference_Location :
Coimbatore
DOI :
10.1109/ICCCNT.2012.6395959