DDoS attack detection method using cluster analysis

作者:

Highlights:

摘要

Distributed Denial of Service (DDoS) attacks generate enormous packets by a large number of agents and can easily exhaust the computing and communication resources of a victim within a short period of time. In this paper, we propose a method for proactive detection of DDoS attack by exploiting its architecture which consists of the selection of handlers and agents, the communication and compromise, and attack. We look into the procedures of DDoS attack and then select variables based on these features. After that, we perform cluster analysis for proactive detection of the attack. We experiment with 2000 DARPA Intrusion Detection Scenario Specific Data Set in order to evaluate our method. The results show that each phase of the attack scenario is partitioned well and we can detect precursors of DDoS attack as well as the attack itself.

论文关键词:DDoS,Proactive detection,Security,Cluster analysis

论文评审过程:Available online 13 February 2007.

论文官网地址:https://doi.org/10.1016/j.eswa.2007.01.040