Robust and efficient detection of DDoS attacks for large-scale internet

Kejie Lu, Dapeng Wu*, Jieyan Fan, Sinisa Todorovic, Antonio Nucci

*Corresponding author for this work

Research output: Journal Publications and ReviewsRGC 21 - Publication in refereed journalpeer-review

79 Citations (Scopus)

Abstract

In recent years, distributed denial of service (DDoS) attacks have become a major security threat to Internet services. How to detect and defend against DDoS attacks is currently a hot topic in both industry and academia. In this paper, we propose a novel framework to robustly and efficiently detect DDoS attacks and identify attack packets. The key idea of our framework is to exploit spatial and temporal correlation of DDoS attack traffic. In this framework, we design a perimeter-based anti-DDoS system, in which traffic is analyzed only at the edge routers of an internet service provider (ISP) network. Our framework is able to detect any source-address-spoofed DDoS attack, no matter whether it is a low-volume attack or a high-volume attack. The novelties of our framework are (1) temporal-correlation based feature extraction and (2) spatial-correlation based detection. With these techniques, our scheme can accurately detect DDoS attacks and identify attack packets without modifying existing IP forwarding mechanisms at routers. Our simulation results show that the proposed framework can detect DDoS attacks even if the volume of attack traffic on each link is extremely small. Especially, for the same false alarm probability, our scheme has a detection probability of 0.97, while the existing scheme has a detection probability of 0.17, which demonstrates the superior performance of our scheme. © 2007 Elsevier B.V. All rights reserved.
Original languageEnglish
Pages (from-to)5036-5056
JournalComputer Networks
Volume51
Issue number18
Online published8 Sept 2007
DOIs
Publication statusPublished - 19 Dec 2007
Externally publishedYes

Research Keywords

  • Detection
  • Distributed denial of service (DDoS) attacks
  • Machine learning
  • Spatial correlation

Fingerprint

Dive into the research topics of 'Robust and efficient detection of DDoS attacks for large-scale internet'. Together they form a unique fingerprint.

Cite this