An automatic and generic early-bird system for internet backbone based on traffic anomaly detection

  • Authors:
  • RongJie Gu;PuLiu Yan;Tao Zou;Chengcheng Guo

  • Affiliations:
  • Department of Electronic Information, WuHan University, WuHan, China;Department of Electronic Information, WuHan University, WuHan, China;Beijing Institute of System Engineering, Beijing, China;Department of Electronic Information, WuHan University, WuHan, China

  • Venue:
  • ICN'05 Proceedings of the 4th international conference on Networking - Volume Part I
  • Year:
  • 2005

Quantified Score

Hi-index 0.00

Visualization

Abstract

Worm and Dos, DDos attacks take place more and more frequently nowadays. It makes the internet security facing serious threat. In this paper, we introduced the algorithm and design of ESTABD, an internet backbone Early-bird System of Traffic Anomaly Detection Based. By observing the raw variables such as packets count of protocol, TCP flags and payload length distribution etc., ESTABD analyzes real-time traffic to discover the abrupt traffic anomalous and generate warnings. A traffic anomaly detection algorithm based on Statistic Prediction theory is put forward and the algorithm has been tested on real network data. Further more, Alerts correlation algorithm and system policy are addressed in this paper to detect the known worms& Dos attacks and potentially unknown threats.