Mathematical modelling of DDoS attack and detection using correlation

Khundrakpam Johnson Singh, Tanmay De · Journal of Cyber Security Technology · 2017

Distributed denial of service attack (DDoS) is one of the top-rated cyber threats currently. It runs down the victim server resources such as bandwidth and buffer size by obstructing the server to provide resources to legitimate clients. In this article, we propose a mathematical model of DDoS attack; we discuss its relation to the features such as inter-arrival time or rate of arrival of the attacking clients accessing the server. We further analyse the attack model in context to exhausting bandwidth and buffer size of the victim server. The proposed method uses an unsupervised learning method, self-organising map, to form the clusters of identical features. Lastly, the article applies mathematical correlation and the normal probability distribution on the clusters and analyses their behaviours to detect a DDoS attack. The article uses the CAIDA 2007 data set for analysing and confirmation of the proposed model.

Read the paper · More papers on PaperTik