Fast Detection of Distributed Global Scale Network Attack Symptoms and Patterns in High-speed Backbone Networks
Sun Ho Kim · KSII Transactions on Internet and Information Systems · 2008
Traditional attack detection schemes based on packets or flows have very high computational complexity.And, network based anomaly detection schemes can reduce the complexity, but they have a limitation to figure out the pattern of the distributed global scale network attack.In this paper, we propose an efficient and fast method for detecting distributed global-scale network attack symptoms in high-speed backbone networks.The proposed method is implemented at the aggregate traffic level.So, our proposed scheme has much lower computational complexity, and is implemented in very high-speed backbone networks.In addition, the proposed method can detect attack patterns, such as attacks in which the target is a certain host or the backbone infrastructure itself, via collaboration of edge routers on the backbone network.The effectiveness of the proposed method are demonstrated via simulation.