Global abnormal correlation analysis method for DDoS attack detection

Yao Xingmiao · Journal of Computer Applications · 2009

DDoS attack is hard to detect in backbone network,for the reason that attack flows are distributed in multiple links and prone to be masked by tremendous amounts of background traffic. To solve this problem,a detection method based on global abnormal correlation analysis was proposed. The change of correlation between traffic caused by attack flows was exploited for attack detection,the correlation between potentially anomalous traffic was extracted by principle component analysis,and its change degree was used as an indicator of attack. Evaluation shows effectiveness of the proposed method,and proves that it overcomes the difficulties in detecting relatively low volume of DDoS attack transiting in backbone network. Compared with the existing network-wide detection method,it achieves higher detection rate.

Read the paper · More papers on PaperTik