DDoS attack detection method based on network traffic and IP entropy

Jungang Yang,Xintong Wang,Guqing Liu
DOI: https://doi.org/10.3969/j.issn.1001-3695.2016.04.041
2016-01-01
Abstract:In-depth research on the low true positive rate and high false positive rate of existing DDoS attack,this paper ana-lyzed the characteristics of network traffic and IP entropy when DDoS attack occured,established the membership function of traffic and IP entropy.It obtained the lower limit parameter and utilization limit parameters of membership function by the real network environment simulation,and proposed a DDoS attack detection algorithm based on the characteristics of network traffic and IP entropy.The method first judged whether the network traffic was abnormal,and then judged whether the entropy was abnormal,then judged whether a DDoS attack was happened.The simulation results show that the separate flow or IP entropy can’t well detect the DDoS attack.The algorithm comprehensively consider of network traffic and IP entropy characteristics, has accurately detected the DDoS attack and decrease false positive rate and improved true positive rate.
What problem does this paper attempt to address?