SYN flooding attack detection based on entropy computing

  • Authors:
  • Martine Bellaïche;Jean-Charles Grégoire

  • Affiliations:
  • Génie Informatique et Génie Logiciel, École Polytechnique de Montréal, Montréal, QC, Canada;INRS, Montréal, QC, Canada

  • Venue:
  • GLOBECOM'09 Proceedings of the 28th IEEE conference on Global telecommunications
  • Year:
  • 2009

Quantified Score

Hi-index 0.01

Visualization

Abstract

We present an original approach to detect SYN flooding attacks from the victim's side, by monitoring unusual handshake sequences. Detection is done in real-time to allow quick protection and help guarantee a proper defence. Our detection system uses an entropy measure to detect changes in the balance of TCP handshakes. Experiment results show that our method can detect SYN flooding attacks with better accuracy and robustness than traditional stateless methods, and with manageable overhead.