On the use of principal component analysis in the entropy based detection of denial‐of‐service attacks

Ilija V. Basicevic, Nikola Blazic, Stanislav Očovaj · Security and Privacy · 2021

Abstract This paper investigates some possibilities for the use of the principal component analysis (PCA) algorithm in the detection of denial‐of‐service (DoS) attacks. Two simple traffic features that are widely used for the detection of DoS attacks are source and destination ports of packets. In this paper, we show that by using only the principal component of these two features as the input for detection a powerful detector can be built. Shannon entropy formula and two generalized entropy formulas have been used in combination with PCA. The input dataset is generated in an emulation testbed. The type of attack that is investigated is SYN flood.

Read the paper · More papers on PaperTik