Defense of DDoS by Using Intrusion Detection Technology
Wang Shi-an · Journal of Petrochemical Universities · 2004
Distributed denial of service (DDoS) performed by multiple hosts is one of the most serious problems in computer and network security, it difficult to detecte and trace. First, the system construction of the DDoS attack model was described, and the principles of DDoS attack were deeply analyzed. Then the example of DDoS attack case was presented. Second, the concepts of intrusion detection technology were summarized. At the last, some models of detection DDoS attack and some technical methods based on intrusion detection to prevent the DDoS from attacking were provided. A network intrusion detection scheme was proposed, which focused on detecting DDoS attacks. The proposed scheme detected if packets passing routers were found anomaly in traffic distribution, which could generate the attack signature as the anomaly in packet field distributions. The proposed scheme is composed of three stages. Packet classification, which can help classify the packets and get the characteristic of network traffic. Traffic dispersion function, which computes the character of the network packets distribution. Variance-based anomaly detection, the network traffic is treated as anomalistic if the variance of statistics exceeds the threshold decided by previous statistics.