Detection of DDoS and DRDoS using Entropy based Approach and Comparative analysis with RCD approach in Networks
Thasneem Abdul Jaleel · 2014
Network security is an important field in the area of computer science. Since everybody make use of computer networks in some form and makes maximum utilization of the networks, the study of attacks in network security is essential. Distributed reflection Denial of Service attacks (DRDoS) and Distributed Denial of Service (DDoS) attack are major threats to the network security. In the proposed system the volume of network traffic is pre-processed by entropy-based methods. Then, by using analysis on the entropy of source IPs and destination IPs, DDoS attacks and DRDoS attacks are detected. In this procedure, a variation fromLyapunov exponent is used to detect attacks. In order to express the rate of separation between source IPs and destination IPs, a variation of Lyapunov exponent of these entropies have been introduced to detect the anomalies in traffic. The system focus on analysing the efficiency of entropy based method against the efficiency of Rank Correlation based detection against DRDoS attacks. Key words-DRDoS, DDoS, Entropy, Lyapunov exponent