Defending against UDP Flooding by Negative Selection Algorithm Based on Eigenvalue Sets
Rui Xu, Wenli Ma, Zheng Wen-ling · 2009
A defense system against UDP flooding attack with artificial immune detection was put forward, and four sections detection with weight was proposed based on considering the uncontinuity of IP address. Eigenvalue matching was introduced based on analyzing the r-continuous bits matching rule. Using the new matching rule the negative selection algorithm was improved both in detector generation and "black hole" detection. The detectors and the eigenvalue filter windows are applied to detect all of nonself modes. Simulation results show that the defense system could effectively detect the fake IP addresses from UDP flooding and insure the server could be accessed by legal users. Also, the consumption of the detection time is not increased significantly.