Development of an indicator to distinguish DDoS attacks from other anomalous events

Paige Piggott, Camille Carter, Wayne Patterson, Fredy Gutierrez, Sergio Mujica, Esteban Rojas, Cristhofer Valenzuela · 2013

Distributed Denial of Service attacks (DDoS) are coordinated efforts, by human or machine, to overwhelm web sites, and at a minimum, to cause them to shut down. The use of this type of malicious software has grown exponentially in the past decade, and despite considerable research, it has proven very difficult to identify, detect or prevent such attacks. On the other hand, increases in traffic at Web sites may not be the result of a DDoS attack, but a legitimate increase in demand for the Web service. Our current research attempts to find indicators that will enable a system or network to distinguish between a DDoS attack and legitimate heavy traffic in real time.

Read the paper · More papers on PaperTik