Detecting DDOS Attack Based on One-Way Connection Density

Tu Xu, Da Jiang He, Yu Zheng · 2006

How to find essential features between normal stream and attack stream and identify the distributed denial of service (DDoS) attack online with simple algorithm are two critical issues in detecting DDoS attack which will contribute to identifying DDoS attack with low false positive and low false negative. According to the features of DDoS attack, a conception of one-way connection density (OWCD) and time serial analysis on OWCD are proposed in this paper. Then a DDoS detecting algorithm based on the mechanism of distance measure of OWCD is also presented. In terms of the experimental results, our detection scheme overcoming the shortage of two-classification detecting methods can efficiently identify the DDoS attack with various attacking intensity

Read the paper · More papers on PaperTik