DoS Detection Model Base on Alive Entropy

LIU Yan-heng,FU Feng,ZHU Jian-qi,SUN Xin
DOI: https://doi.org/10.13229/j.cnki.jdxbgxb2011.04.012
2011-01-01
Abstract:An alive entropy model is proposed for detecting increasingly serious Denial of Service(DoS) attacks.The model is based on the theory of active communication that combines the information entropy and related sessions of network flow.The model detects DoS attacks through the analysis of the variation of the network flow's alive entropy.Experiment result show that the alive entropy is stable under normal network flow,and when attack occurs it fluctuates obviously.Compared with other methods based on the static entropy model,the proposed model is more accurate and more effective in detecting unknown DoS attack.
What problem does this paper attempt to address?