Ensemble-based model for DDoS attack detection and flash event separation
Sajal Bhatia · 2016
Distributed Denial-of-Service (DDoS) attacks continue to constitute a pernicious threat to the delivery of services within the Internet domain. These attacks harness the power of thousands, and sometimes tens or hundreds of thousands of compromised computers to attack web-services and online trading sites, resulting in significant down-time and financial loss. The problem of detecting DDoS attacks is complicated by Flash Events (FEs), which share some characteristics with DDoS attacks, and which occur when a server experiences an unexpected surge in requests from legitimate clients. This paper presents the design and implementation of an ensemble-based DDoS attack detection and FE separation model, which combines two orthogonal anomaly-based attack detection strategies viz., network traffic analysis and server-load analysis. Using an Exponentially Weighted Moving Average (EWMA) technique, changes in individual network and server load metrics are first detected and then correlated to identify a variety of DDoS attacks, both at the network and the application layer, and to differentiate them from FE and normal traffic scenarios.