Clustering Based DDoS Attack Detection Using The Relationship Between Packet Headers
Çağatay Ateş, Süleyman Özdel, Emin Anarım · 2019 Innovations in Intelligent Systems and Applications Conference (ASYU) · 2019
Distributed Denial of Service (DDoS) attacks burden a huge threat to the internet society. Multiple infected computers commanded by the attacker execute the attack to overwhelm the target. In this paper, we propose a DDoS attack detection method based on non-parametric community clustering algorithm. It is applied using the connections between the source and destination sides of packet headers. Main advantage of this clustering algorithm is that it does not require any predetermined parameters compared to classical clustering algorithms such as k-Means algorithm. For evaluating the clustering process, two metrics are used which are modularity and normalized entropy. They perform significant changes during the attack traffic. To detect these changes, Support Vector Machine (SVM) is utilized. This proposed algorithm is tested on the real data collected from Boğaziçi University network and Caida dataset.