DDoS Attack Detection Based on Correlation of Macro Network Flow

Shirui Zhu · Jisuanji gongcheng · 2011

Aiming at the defects such as detection efficiency is still low,the application scope is narrow in currently detection methods,based on analyzing the impact of the correlation of traffic size and IP address caused by Distributed Denial of Service(DDoS) attacks,this paper proposes a method of detecting DDoS attacks based on the correlation of network flow,analyses the correlation of traffic size,defines the rate of variance of hurst exponent as the measure to distinguish the normal traffic and abnormal traffic which cause the original traffic increase notable.The correlation of IP address is analysed,flash traffic and DDoS attacks through the measure of degree of similarity are distinguished.Result shows that through combine correlation analysis of traffic size and IP address,it can distinguish DDoS attacks traffic from normal traffic and burst traffic,and raise the detection efficiency.

Read the paper · More papers on PaperTik