2nd International Symposium on Big Data and Cloud Computing (ISBCC'15) DDoS Attack Detection using Fast Entropy Approach on Flow - Based Network Traffic

Jisa David, Ciza Thomas · 2015

Denial of service attack and Distributed Denial of Service att acks are becoming an increasingly frequent disturbance of the global Internet. In this paper we propose improvement in detection of Distributed Denialattacks based on fast entropy method using flow-based analysis. An adaptive threshold algorithm is made use of since both network activities and user's behavior could vary over time. Fast Entropy and flow -based analysis show significant reduction in computational time compared to conventional entropy computation while maintaining good detection accuracy. The network traffic is analyzed and fast entropy of request per flow is calculated. DDoS attack is detected when the difference between entropy of flow count at eac h instant and mean value of entropy in that time interval is greater than the threshold value that is updated adaptively based on traffic pattern condition to improve the detection accuracy.

Read the paper · More papers on PaperTik