Design and Development of Denial of Service (DoS) Detection Algorithm Based on the Analysis of Activity Profiling and Change-Point Monitoring Denial of Service Attack Detection Techniques
Jo Seczar Z. Cavero, Leonel T. Deligero, Jacquelyn L. Gotgot, Nickeleus A. Saduca, Roy Leonardo O. Siroy, Linda E. Saavedra · ICEIC : International Conference on Electronics, Informations and Communications · 2010
Denial-of-Service (DoS) attack is one type of epidemic in an internetworking infrastructure that demands an effective detection method. This study presents an algorithm that is modeled from our analysis of results of Activity Profiling and Change Point Monitoring algorithms in detecting five DoS attacks - ICMP Echo Flood DDoS, Ping of Death, UDP Flood, TCP SYN and DDoS. Here, we named the algorithm Exemplar. Additionally, a packet sniffer was developed as a component of Exemplar. Exemplar showed better performance in terms of the number of attacks detected, detection probability and average detection speed.