DDos detection system based on similarity analysis
Fan Jiang · Computer-aided engineering · 2005
A model of Distributed Denial of Service (DDos) detection system is proposed. Creat network data and server’s status characteristic set by characteristic set algorithm are based on cluster analysis. The similarity between user’s behavior and characteristic set is calculated to detect DDos attack and update characteristics set. Especially, three improving steps, which are data normalization, attribute weighting and combination of weighting change, are adopted to enhance detection accuracy. At last, the effect of this model is proved by simulation on LAN.