A traffic tracking algorithm for a fast detection of active network sources
Ayah Atiyah, Sufyan Almajali · 2018
Denial of Service attack is a cyber-attack that overwhelms the victim resources (system resources and network bandwidth) and makes them unavailable to legitimate users. To take the edge of this problem, packet filtering schemes at the front end of network monitoring systems (such as an Intrusion Detection System) have been proposed. Detecting suspicious activities and abnormal high traffic activities are challenging tasks as existing packet filtering and monitoring algorithms perform poorly when the given time budget of execution is minimum. Satisfying such a standard requires a packet filtering algorithm to be capable of controlling its execution time to provide much superior average case performance. Our proposal consists of developing a traffic monitoring algorithm that uses Binary Search Tree along with a shortcut to speed up the detection of active traffic sources in the network. The research paper presents the performance efficiency and the time complexity of the proposed algorithm. Results show that the shortcut traffic monitoring algorithm will result in performance improvement compared to the conventional algorithms of detecting top active nodes. This can be utilized in detecting quickly suspicious active nodes and take early actions.