Detection of Sources Being Used in DDoS Attacks
Yalda Khosroshahi, Enver Ozdemır · 2019
Distributed Denial of Service (DDoS) detection is one of the challenging topics in cyber defense realm. Detection of this type of attack in the early stages can be beneficial. In this paper, we propose an entropy-based detection framework using Support Vector Machine (SVM) classification algorithm to detect sources being used in DDoS attacks. This method can prevent Denial of Service (DoS) attack from proceeding in source devices which are involved in a DDoS botnet attack. By intercepting outgoing packets from an Android device, proposed framework extract packet features in a specific time window. Normal and abnormal network behavior of a user will be logged and analyzed using SVM algorithm. The obtained model will be used as a detection system for malicious activities.