DDoS Attack Detection Algorithm Using IP Address Features

  • Authors:
  • Jieren Cheng;Jianping Yin;Yun Liu;Zhiping Cai;Min Li

  • Affiliations:
  • School of Computer, National University of Defense Technology, Changsha, China 410073 and Department of mathematics, Xiangnan University, Chenzhou, China 423000;School of Computer, National University of Defense Technology, Changsha, China 410073;School of Computer, National University of Defense Technology, Changsha, China 410073;School of Computer, National University of Defense Technology, Changsha, China 410073;School of Computer, National University of Defense Technology, Changsha, China 410073

  • Venue:
  • FAW '09 Proceedings of the 3d International Workshop on Frontiers in Algorithmics
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

Distributed denial of service (DDoS) attack is one of the major threats to the current Internet. After analyzing the characteristics of DDoS attacks and the existing Algorithms to detect DDoS attacks, this paper proposes a novel detecting algorithm for DDoS attacks based on IP address features value (IAFV). IAFV is designed to reflect the essential DDoS attacks characteristics, such as the abrupt traffic change, flow dissymmetry, distributed source IP addresses and concentrated target IP addresses. IAFV time series can be used to characterize the essential change features of network flows. Furthermore, a trained support vector machine (SVM) classifier is applied to identify the DDoS attacks. The experimental results on the MIT data set show that our algorithm can detect DDoS attacks accurately and reduce the false alarm rate drastically.