DDoS attack detection method based on conditional random field with feature set

CHEN Shiwen,WU Jiangxing,HUANG Wanwei
DOI: https://doi.org/10.3778/j.issn.1002-8331.1302-0182
2013-01-01
Abstract:The traditional detection methods for DDoS attacks have low accuracy and high false alarms rate because those means are only based on one of such flow features as burst feature,dispersed source IP address,asymmetry flow and etc.This paper uses conditional random field to integrate many pattern match rules for DDoS attack detection.The feature vector includes one way connection density,source IP entropy,destination IP entropy,destination port entropy and protocol entropy.The simulation results show that the proposed method outperforms other well-known methods such as na ve Bayes and SVM.The detection accuracy rate reaches 99.82% and the false alarm rate is less than 0.6%.The method is robustness under strong interference traffic noise.
What problem does this paper attempt to address?