An Integrated Victim-based Approach against IP Packet Flooding Denial of Service
Ruth Mbabazi Mutebi, Azlina Idris · 2010
In this work, we designed a detection technique from a combination of three existing anomaly detection algorithms to detect attacks at the victim machine. The technique is a combination the cumulative sum algorithm (CUSUM), the source IP monitoring algorithm (SIM), and the adaptive threshold algorithm. It is made up of parallel and sequential steps where by the CUSUM and SIM algorithms are designed to work in parallel terms, while the adaptive threshold algorithm is run in case the results from the two (i.e., CUSUM and SIM) are conflicting. We used simulations to evaluate the performance of the proposed technique under various attack scenarios. The results show that the proposed integrated approach is capable of detecting a much wider range of attacks and even flash crowds, compared to the individual algorithms in isolation.