Entropy-score: A method to detect DDoS attack and flash crowd

Akshat Gaurav, Awadhesh Kumar Singh · 2017

Nowadays the Internet plays a vital role in the growth of the economy for any nation. DDoS attacks are one of the major threat that hurting this growth as it affects the systems and network which uses the Internet for their business work. In DDoS attacks, victims bandwidth is flooded with the excessive amount of malicious or fake traffic due to which, the victim is unable to serve the legitimate users. There have been many different techniques proposed by the researchers which can detect DDoS attack efficiently. But they have many limitations and one of the important limitation of these techniques is their inability to differentiate flash crowd from DDoS attacks. Flash crowd is a scenario in which plenty of legitimate users tries to access a common server or system, so filtering of this kind of traffic may lead to business loss or credibility loss of the victim. In this context, we proposed a new detection method, Entropy-score. Which uses a hierarchical structure to analysis the incoming packets. In the proposed approach first, the entropy-based method is used for characterizing the incoming packets and then packet score based method is used for filtering the malicious packets. We implement this proposed method by using OMNET++ simulation tool and the experimental results show that Entropy-score method not only differentiates DDoS attacks traffic from Flash crowd but can also differentiate the attack traffic from the normal traffic.

Read the paper · More papers on PaperTik