E-LDAT: a lightweight system for DDoS flooding attack detection and IP traceback using extended entropy metric
Monowar Bhuyan, Dhruba K. Bhattacharyya, Jugal Kalita
Abstract
Monowar Bhuyan, Dhruba K. Bhattacharyya, Jugal Kalita
Abstract
Distributed denial-of-service DDoS attacks cause havoc by exploiting threats to Internet services. In this paper, we propose E-LDAT, a lightweight extended-entropy metric-based system for both DDoS flooding attack detection and IP Internet Protocol traceback. It aims to identify DDoS attacks effectively by measuring the metric difference between legitimate traffic and attack traffic. IP traceback is performed using the metric values for an attack sample detected by the detection scheme. The method uses a generalized entropy metric with packet intensity computation on the sampled network traffic with respect to time. The E-LDAT system has been evaluated using several real-world DDoS datasets and outperforms competing methods when detecting four classes of DDoS flooding attacks, including constant rate, pulsing rate, increasing rate and subgroup attacks. The IP traceback model is also evaluated using NetFlow data in near real-time and performs well in large-scale attack networks with zombies. Copyright © 2016 John Wiley & Sons, Ltd.
OpenAlex reports 45 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Distributed denial-of-service DDoS attacks cause havoc by exploiting threats to Internet services. In this paper, we propose E-LDAT, a lightweight extended-entropy metric-based system for both DDoS flooding attack detection and IP Internet Protocol traceback. It aims to identify DDoS attacks effectively by measuring the metric difference between legitimate traffic and attack traffic. IP traceback is performed using the metric values for an attack sample detected by the detection scheme. The method uses a generalized entropy metric with packet intensity computation on the sampled network traffic with respect to time. The E-LDAT system has been evaluated using several real-world DDoS datasets and outperforms competing methods when detecting four classes of DDoS flooding attacks, including constant rate, pulsing rate, increasing rate and subgroup attacks. The IP traceback model is also evaluated using NetFlow data in near real-time and performs well in large-scale attack networks with zombies. Copyright © 2016 John Wiley & Sons, Ltd.
Key concepts: Denial-of-service attack, Computer science, Ip address, Flooding (psychology), IP traceback, Application layer DDoS attack, Computer network, Metric (unit)