Peak Traffic Volume Prediction Method Based on Machine Learning

Shuang Wei,Yijing Ding,Tongxin Li,Shuaifu Dai,Xinfeng Wu,Xinhui Han
2017-01-01
Abstract:DDoS defense nowadays relies on expensive and proprietary hardware appliances. When a massive attack begins, improper choices such as choosing fewer appliances or those without enough capacity may lead to more severe damage. As the previous work proposed[1], the choice heavily depends on the peak volume of the attack traffic(measured by packets per second). However, no prediction methods have been proposed to the best of our knowledge. In this paper we propose a method called DDoSPVPredictor to predict the peak volume of the DDoS traffic both effectively and efficiently. Based on machine learning, DDoSPVPredictor can predict the peak with only 24 features and for each attack the procedure can be finished in about 1.2s. We evaluate our solution’s prediction accuracy using the 1998 MIT DARPA dataset. Result shows that DDoSPVPredictor is able to predict the peak volume of attack traffic with an accuracy of 85%. Therefore DDoSPVPredictor can help a lot in defending against massive DDoS attacks by optimizing its mitigation method using the predicted outcome.
What problem does this paper attempt to address?