Detection method against SYN Flooding attacks based on source end by analysis of time series

Yang Bong Su · Jisuanji yingyong yanjiu · 2012

This paper proposed a method of detecting DDoS attacks based on source end by analyzing the abrupt change of time series data.By detecting and predicting the data flow in the Internet at source end,the method could judge whether SYN Flooding was occurred or not for providing the foundation for the victim end.It extracted the characteristic information of data flow by using the self-similarity of network traffic flow and Bloom Filter algorithm,so that it could construct the time series of the network traffic flow and build the auto-regressive(AR) forecasting model.By dynamically forecasting traffic flow and comparing with definite threshold,pre-alert was sent and response was ahead adopted.The experimental results show that the scheme can count the number of the data packages and the number of the new IP data packages with the better detection rate and lower misinformation rate,besides,it can predict the traffic flow in the next period even several periods correctly,which can provide strong support for effectively defending against SYN Flooding attacks.

Read the paper · More papers on PaperTik