Detection of application-layer DDoS attack based on time series analysis
Hui Ding · Journal of Computer Applications · 2013
According to the difference between normal users' visiting patterns and abnormal ones,a new method to detect application-layer Distributed Denial of Service(DDoS) attack was proposed based on IP Service Request Entropy(SRE) time series.By approximating the Adaptive AutoRegressive(AAR) model,the SRE time series was transformed into a multidimensional vector series regarded as a description of current users' visiting patterns.Furthermore,a Support Vector Machine(SVM) classifier was applied to classify vector series and identify the attacks.The simulation results show that this approach not only can distinguish between normal traffic and DDoS attack traffic,but also is suitable to detect DDoS attack against the large scale network traffic,which does not arouse the sharp changes of the network traffic.