Dynamic Model of Non-stationary Behavior and Its Application in Detecting DDoS Attacks

XIE Yi,TANG Cheng-hua,HUANG Xiang-nong
DOI: https://doi.org/10.3969/j.issn.1000-1220.2013.09.027
2013-01-01
Abstract:Application-layer DDoS attack is a main threat to most of modern network service providers.The main drawback of conventional detection methods is that they are hard to describe the non-stationary and time-varying user behavior and cannot automatically adjust the model parameters according to the evolution of normal user behavior.In this paper,a new dynamic application-layer DDoS detection approach is proposed.The proposed scheme utilizes semi-Markov chain to describe the profile of normal behavior.A new dynamic recursive algorithm is introduced to adjust the model's parameters.The model is applied to detect the Application-layer DDoS attacks.Experiments based on a real trace are implemented to validate the proposal.
What problem does this paper attempt to address?