FVBA: A combined statistical approach for low rate degrading and high bandwidth disruptive DDoS attacks detection in ISP domain
Brij Bhooshan Gupta, Manoj Kumar Misra, Ramesh Chander Joshi · 2008
Distributed denial of service (DDoS) attack is one of the latest and most powerful threats that have appeared to the Internet. The main aim of such attacks is to prevent access to resources by legitimate users for which they have authorization. In this paper, a novel flow-volume based DDoS detection approach (FVBA) is proposed, which deals with detection of variety of DDoS attacks by monitoring the propagation of abrupt traffic changes inside ISP Domain. Two statistical measures namely volume and flow are used as parameters to detect DDoS attacks. NS-2 network simulator on Linux platform is used as simulation testbed. Different attack scenarios are implemented by varying total number of zombie machines and at different attack strengths to measure effectiveness of proposed approach. Our simulation results show that FVBA inflicts an extremely high detection rate with low false alarm rate.