Detecting Distributed Denial of Service Attack Based on Multi-feature Fusion.

Jieren Cheng,Jianping Yin,Yun Liu,Zhiping Cai,Chengkun Wu
DOI: https://doi.org/10.1007/978-3-642-10847-1_17
2009-01-01
Abstract:Detection of Distributed denial of service (DDoS) attacks is currently a hot topic in both industry and academia. We present an IP flow interaction algorithm (IFI) merging multi-feature of normal flow and DDoS attack flow. Using IFI time series describe the state of network flow, we propose an efficient DDoS attack detection method based on IFI time series (DADF). DADF employs an adaptive parameter estimate algorithm and detects DDoS attack by associating with the states of IFI time series and an alert evaluation mechanism. Experiment results demonstrate that IFI can well fuse the multiple features of normal flow and DDoS attack flow and it is efficient to be used to distinguish normal flow from DDoS attack flow; DADF can fast detect DDoS attack with higher detection rate and lower false alarm rate under relatively large normal background flows.
What problem does this paper attempt to address?