Distinguishing DDoS Attack from Flash Event Using Real-World Datasets with Entropy as an Evaluation Metric

Deepika Mahajan, Monika Sachdeva · 2013

DDoS attack distributed nature causes immense danger to network security. Their ability to send large amount of malicious traffic through multiple agents is a barrier in defending these attacks. Their detection still remains exigent. The situation gets worst as these attacks share similar characteristics with Flash Events where large quantity of legitimate requests come to server on spread of a newsworthy event. In this paper, we classify the DDoS attack from Flash Event using entropy as a metric based on randomness of source IP addresses on a web server. In this work, real-world datasets are used depicting real time scenario of both DDoS attack as well as Flash Event.

Read the paper · More papers on PaperTik