Application of anomaly detection algorithms for detecting SYN flooding attacks

被引:78
作者
Siris, VA
Papagalou, F
机构
[1] Fdn Res & Technol Hellas, FORTH, Inst Comp Sci, GR-71110 Iraklion, Greece
[2] Univ Crete, Dept Comp Sci, Iraklion, Greece
关键词
denial of service; change point detection; network security;
D O I
10.1016/j.comcom.2005.09.008
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
We investigate statistical anomaly detection algorithms for detecting SYN flooding, which is the most common type of Denial of Service (DoS) attack. The two algorithms considered are an adaptive threshold algorithm and a particular application of the cumulative sum (CUSUM) algorithm for change point detection. The performance is investigated in terms of the detection probability, the false alarm ratio, and the detection delay, using workloads of real traffic traces. Particular emphasis is on investigating the tradeoffs among these metrics and how they are affected by the parameters of the algorithm and the characteristics of the attacks. Such an investigation can provide guidelines to effectively tune the parameters of the detection algorithm to achieve specific performance requirements in terms of the above metrics. (C) 2005 Elsevier B.V. All rights reserved.
引用
收藏
页码:1433 / 1442
页数:10
相关论文
共 12 条
[1]  
Basseville M, 1993, DETECTION ABRUPT CHA
[2]  
BLAZEK RB, 2001, P IEEE WORKSH SYST M
[3]  
BRUTLAG J, 2000, P LISA, V14
[4]  
CHENG CM, 2002, P IEEE GLOB 02 NOV
[5]  
COPPENS J, 2004, P 2 INT WORKSH INT D
[6]   A statistical approach to predictive detection [J].
Hellerstein, JL ;
Zhang, F ;
Shahabuddin, P .
COMPUTER NETWORKS, 2001, 35 (01) :77-95
[7]  
HELLERSTEIN JL, 1998, P COMP MEAS GROUP
[8]  
HOOGENBOOM P, 1993, P USENIX SUMM 1993 T
[9]  
HUANG P, 2001, P ACM SIGCOMM INT ME
[10]  
MOORE D, 2001, P USENIX SEC S