Detection of UDP-flood attack with hidden Markov models

Junghun Park, Lei Huang, C.‐C. Jay Kuo · Proceedings of SPIE, the International Society for Optical Engineering/Proceedings of SPIE · 2004

A scheme that uses the hidden Markov model (HMM) is proposed in this work to detect unauthorized nuisance packets in IP networks, which waste network resources and may result in the denial of service (DoS) attack. The proposed HMM is designed to differentiate the attack traffic from the normal traffic systematically. The design of the basic HMM model is first introduced, and the operations of the detector are then described in detail. Finally, we show that the detector using HMM is not sensitive to various attack types and able to detect the attack at an earlier stage.

Read the paper · More papers on PaperTik