On the Collaborative Inference of DDoS: A Multi-scale Distributed Approach

Fatima Ezzahra Ouerfelli, Khaled Barbaria, Belhassen Zouari · 2017

DDoS attacks are becoming increasingly harmful and destructive, especially when multinational companies and government e-services are targeted. Monitoring large scale networks, naturally, involves the processing of an increasingly large quantity of data. While DDoS attacks are by definition distributed and the hackers have access to many (real and virtual) machines, the majority of defense systems are still centralized. In this paper, we present a solution to the scalability problem in DDoS detection and mitigation systems. We simultaneously allow a distributed inference of DDoS attacks, and solve the, so called, "single point of failure" problem by using the paxos consensus protocol. We also demonstrate that wavelet compression methods allow the collaborating probes to analyse a reduced set of traffic without impacting the overall reliability of our DDoS detection system. The Empirical evaluations based on the Booters dataset 1 demonstrate that the proposed approach is indeed capable to cooperatively infer DDoS attacks while achieving scalability and reliability.

Read the paper · More papers on PaperTik