A DDoS Detection Mechanism Based on Flow Analysis
Miao Chen, Jie Yang, Weimin Li, Zhenming Lei · International Conference on Electronics, Communications and Control · 2012
DDoS (Distributed Denial of Service) is a kind of attack that has made great threats to network security. DDoS traffic occupies so much bandwidth that other normal Internet services are disabled. This paper designs a DDoS Monitor based on flow analysis to detect DDoS traffic. Alert will be given if DDoS is detected. Flow records are quite useful for understanding network behavior. DDoS Monitor gets rate information by analyzing flow records. At the beginning, DDoS Monitor works at training mode, meaning that flow records are used as training data to generate thresholds. Then it turns to detection mode to detect DDoS by judging if thresholds are exceeded. Experiments on a large flow data set from an ISP network revealed that DDoS Monitor effectively detected abnormal traffic from flow analysis.