DocumentCode
74547
Title
A System for Denial-of-Service Attack Detection Based on Multivariate Correlation Analysis
Author
Zhiyuan Tan ; Jamdagni, Aruna ; Xiangjian He ; Nanda, Priyadarsi ; Ren Ping Liu
Author_Institution
Sch. of Comput. & Commun., Univ. of Technol., Sydney, Broadway, NSW, Australia
Volume
25
Issue
2
fYear
2014
fDate
Feb. 2014
Firstpage
447
Lastpage
456
Abstract
Interconnected systems, such as Web servers, database servers, cloud computing servers and so on, are now under threads from network attackers. As one of most common and aggressive means, denial-of-service (DoS) attacks cause serious impact on these computing systems. In this paper, we present a DoS attack detection system that uses multivariate correlation analysis (MCA) for accurate network traffic characterization by extracting the geometrical correlations between network traffic features. Our MCA-based DoS attack detection system employs the principle of anomaly based detection in attack recognition. This makes our solution capable of detecting known and unknown DoS attacks effectively by learning the patterns of legitimate network traffic only. Furthermore, a triangle-area-based technique is proposed to enhance and to speed up the process of MCA. The effectiveness of our proposed detection system is evaluated using KDD Cup 99 data set, and the influences of both non-normalized data and normalized data on the performance of the proposed detection system are examined. The results show that our system outperforms two other previously developed state-of-the-art approaches in terms of detection accuracy.
Keywords
computer network security; correlation methods; geometry; interconnected systems; telecommunication traffic; KDD Cup 99 data set; MCA-based DoS attack detection system; attack recognition; computing systems; denial-of-service attack detection; geometrical correlations; interconnected systems; multivariate correlation analysis; network attackers; network traffic; Computer crime; Correlation; Feature extraction; Labeling; Servers; Telecommunication traffic; Training; Denial-of-service attack; multivariate correlations; network traffic characterization; triangle area;
fLanguage
English
Journal_Title
Parallel and Distributed Systems, IEEE Transactions on
Publisher
ieee
ISSN
1045-9219
Type
jour
DOI
10.1109/TPDS.2013.146
Filename
6519239
Link To Document