Global Detection of DDoS Attack Based on Time and Frequency Analysis

Luo Hua,Guang-Min Hu,Xing-Miao Yao
DOI: https://doi.org/10.1109/icccas.2007.6251606
2007-01-01
Abstract:Due to the complicated and distributed characters of DDoS attack, a novel detection DDoS method based on global network is presented in this paper. Our method detects DDoS by analyzing network-wide traffic, whereas the traditional methods detect it on single link or victim network, they can only detect the DDoS which show large scope. Our method was carried out as follows: First, we get network traffic matrix. Then we diagnose DDoS in time domain and frequency domain by K-L transformation and computing correlation coefficient. K-L divides time domain and frequency domain sequence into normal space and abnormal space and then we compute the abnormal space's correlation coefficient. Finally, we set threshold to detect DDoS attack. The simulation result shows that some DDoS could be detected in time domain but others could only be detected in frequency domain. This method is more accurate and faster than traditional ones. It is well suited for detecting earlier DDoS attack.
What problem does this paper attempt to address?