Low-rate DoS Attack Detection Based on WPD-EE Algorithm
Xiaocai Wang, Qiuwei Yang, Zichao Xie, Zhiqing Zheng, Yudong Yan, Dan Tang · 2020
Low-rate Denial of Service (LDoS) attack can greatly degrade the performance of the attacked service by exploiting the security vulnerability in the adaptive mechanism of network protocol. This attack is destructive and awfully covert. For the low accuracy and high complexity of the existing algorithms, this paper proposes a method of attack detection based on WPD-EE. When LDoS attack occurs, TCP congestion control is forced to trigger frequently, which causes a large number of packet loss, resulting in strong periodic fluctuations and discrete characteristics of TCP traffic. Based on the characteristics caused by this LDoS attack, wavelet packet decomposition is carried out for TCP traffic sequence analysis, and then the decomposed node coefficients are reconstructed, so that each signal can reflect the information of TCP traffic influencing factors. Through the calculation of the difference of energy entropy to analyze whether the traffic sequence has discrete characteristics, so as to realize the effective detection of LDoS. Due to the advantages of wavelet packet analysis for more detailed high-frequency signal processing, the method proposed in this paper has high accuracy. In this paper, NS-2 experimental platform, WIDE2018 dataset and TestBed are used for multiple experiments. Experiments show that the proposed algorithm has high accuracy and low false positive rate, which has better advantages than the other related algorithms, and can detect LDoS attack effectively.