Automatic alerts annotation for improving DDoS mitigation systems

Ah Reum Kang, Aziz Mohaisen · 2016

Distributed Denial of Service (DDoS) attacks have been on the rise [1]. With the use of Botnets, an attacker can bring down vital applications and services available on the Internet [2], [3]. Several commercial DDoS mitigation services are available including those by Verisign [4], GigeNET [5], BlockDOS [6], Black Lotus [7], and Arbor Networks [8], among others. A majority of these commercial services use a combination of specialized hardware and a rule-based software to flag suspected traffic and alert the operators for further attentions. In this work, our goal is to design a system to reduce the false positive alerts generated by the existing DDoS mitigation in place while capturing all of the true alerts. To this end, we present a preliminary analysis of real DDoS data collected in operations. Furthermore, in this work we propose a system that uses machine learning techniques to work in tandem with the existing rule-based system to ease the burden on the mitigation team. Additionally, we analyze the alerts generated by the system and provide suggestions to improve the working of the existing DDoS mitigations system.

Read the paper · More papers on PaperTik