EBDT: A method for detecting LDoS attack

Kai Chen, Huiyu Liu, Xiaosu Chen · 2012

The Low-rate Denial of Service (LDoS), as a new type of DoS, is more difficult to be detected due to its concealment and variety. However, whenever a kind of LDoS attack occurs, the TCP traffic becomes unusual: its distribution and decreased degree are significantly different than those without any LDoS attacks. Based on these characteristics, a method for detecting LDoS attacks called EBDT is proposed, which detects LDoS attacks by analyzing the variation of TCP traffic. Simulations show that EBDT can detect LDoS attacks effectively and the testing results with the real network traffic show that EBDT has a low false-positive rate.

Read the paper · More papers on PaperTik