A DoS Attack Defense Model Adopting Data Mining

Bin TONG,Zhi-guang QIN,Wei-feng JIA,Jian-wei SONG
DOI: https://doi.org/10.3969/j.issn.1001-0548.2008.04.029
2008-01-01
Abstract:According to the characteristics of DoS/DDoS attack, a defense model adopting data-mining technology is proposed. Based on real-time sample traffic, this model extracts trusted IP list by association analysis to filter, and evaluates packets' danger degree by adopting bayes algorithm. This model makes up disadvantages of traditional filtering based on trusted source IP, and effectively differentiates normal traffic and abnormal traffic. Experimental datum proves this model can launch real-time and effective defense against DoS/DDoS attack.
What problem does this paper attempt to address?