Suspicious traffic detection based on edge gateway sampling method
Sinh-Ngoc Nguyen, Jintae Choi, Kyungbaek Kim · 2017
Packet sampling is commonly deployed in all of Intrusion Detection System (IDS) to block the resources consumed from DDoS attack in the network. The IDS usually places sample collector either at distributed points in the network or next to the victim. The sampling methods use the threshold of traffic to detect the attack. It will stop an attack if having a matching with the threshold which is defined in the rule of IDS. We assume that there are lots of suspicious traffics with small volume going to the same destination. The IDS with distributed sampling method cannot detect these traffics. Because of small volume of suspicious traffic, it is not large enough to match the threshold in the rule. Although suspicious traffics have small volume, lots of the traffics generate a large volume at the same destination of victim. To handle this problem, placing the sample collector next to the victim and implementing the destination rule in IDS are proposed, the destination rule can detect multiple traffics that have the same destination IP. However, it still gets the problem that it lets the suspicious traffic going through the network, which generates a large number of unnecessary traffics and causes to the low performance of network. In this paper, we propose a sampling based approach that samples the traffic at the edge gateway in a Software Defined Networking (SDN) based network. It could detect the DDoS attack earlier before reaching to the complex core network, and it could determine which domain the DDoS attack comes from.