DoS/DDoS Detection Scheme Using Statistical Method Based on the Destination Port Number

Shunsuke Oshima, Arata Hirakawa, Takuo Nakashima, Toshinori Sueyoshi · 2009

To defend DoS (Denial of Service) attacks, an access filtering mechanism is adopted in the firewall. The difficulty to define the filtering rules lies where normal and anomaly packets have to be distinguished in incoming packets. The purpose of our research is to explore the early detective method for anomaly accesses based on statistic analysis. In this paper, we defined the chi-square method, and then conducted analyses the all amount of incoming packets to our College. As the results, we extracted the following features. Firstly, the chi-square analysis based on the destination port number is more sensitive to the DDoS attacks and IP scan than that based on the destination IP address. Secondly, DoS attacks raise the chi-square value up based on the analysis of the destination IP address. Finally, the multiplexing DoS attacks tend to reduce the chi-square values in both analyses.

Read the paper · More papers on PaperTik