A Distributed Detection Scheme Based on Weighted CAT against DDoS
Yang Xiao-hong · Journal of Wuhan University · 2008
In order to solve the problem about heavy overhead at the victim end and low detection rate in DCD scheme,a new detection scheme is proposed based on weighted CAT.By designing a Multi-tier distributed architecture,the detection task is distributed to the source end,the intermediate network,and the victim end over the Internet to implement the early detection of attacks.Using the sensitivity of CUSUM algorithm to slight changes,the detection is carried out based on the quantity of outgoing packets to a destination address at the source end host as well as the super stream aggregation change at the intermediate network.The victim end detection is based on the weight of AS tree.Experimental results and analysis indicate that the detection rate for UDP attacks is raised from 0.72 in DCD to 0.94 in CAT and the detection rate for TCP attacks is improved too;the overhead of the network communication and the storage is reduced from o(mnk) to o(mk),the cost of computation from o(mn) to o(m).The system attains the attack path and the exact host or router or domain where the anomaly is observed during the detection of suspicious abnormality.Once a DDoS attack is detected,the distributed traceback is performed.