Detecting Distributed Denial of Service Attacks Based on Time Series Analysis

Sun Qin · Chinese Journal of Computers · 2005

On the basis of analyzing of the features of distributed denial of service (DDoS) attacks, a novel approach of detection of DDoS attacks based on flow connection density (FCD) time series analysis is proposed. By approximating the adaptive autoregression model, the FCD time series is transformed into a multidimensional vector series regarded as a description in multidimensional space of state of current network flow, and then a trained support vector machine (SVM) classifier is applied to identify the attacks from the multidimensional vector series. Furthermore, by considering the interval and distribution of alerts, an algorithm evaluating reliability of alert is developed to reduce the false positives caused by flow noise and classification errors. The experiments demonstrate that the approach can detect DDoS attacks effectively, and the proposed algorithm can reduce the false positive drastically.

Read the paper · More papers on PaperTik