Denial of Service Attack Detection using Multivariate Correlation Analysis
Nazrul Hoque, Dhruba K. Bhattacharyya, Jugal Kumar Kalita · 2016
Denial of Service (DoS)/ DDoS attack is a common and severe problem for network security researchers and practitioners. Attackers often generate attack traffic that behaves similar to normal network traffic using sophisticated attacking tools. Many intrusion detection systems fail to detect anomalous packets in real time. In this paper, we use a Multivariate Correlation Analysis (MCA) approach to distinguish attack traffic from normal traffic. This statistical measure is used to analyze the behavior of network traffic for attack detection. Since DDoS attack traffic behaves differently from legitimate network traffic, statistical properties of various parameters reflect the changed behavior of network traffic. We extract three basic parameters of network traffic, viz., entropy of source IPs, variation of source IPs and packet rate to analyze the behavior of network traffic during attack detection. The method is validated using several benchmark datasets.