An attack classification mechanism based on multiple support vector machines

  • Authors:
  • Jungtaek Seo

  • Affiliations:
  • National Security Research Institute, Daejeon, Republic of Korea

  • Venue:
  • ICCSA'07 Proceedings of the 2007 international conference on Computational science and Its applications - Volume Part II
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

DDoS attack methods become more sophisticated and effective. An attacker combines various attack methods, and as a result, attacks become more difficult to be detected. In order to cope with these problems, there have been many researches on the defense mechanisms including various DDoS detection mechanisms. SVM is suitable for attack detection since it is a binary classification method. However, it is not appropriate to classify attack categories such as SYN Flooding attack, Smurf attack, UDP Flooding, and so on. Because of this weakness, administrator does not react against the attack timely. To solve this problem, we propose a machine learning model based on Multiple Support Vector Machines (MSVMs), and a new DDoS detection model based on Multiple Support Vector Machines (MSVMs). The proposed model enhanced attack detection accuracy and it classifies attack categories well when the proposed model detects the attacks.