DoS Detection System Based on Dynamic Thresholding Algorithm using Netflow and Elasticsearch
Adian Fatchur Rochim, Muhammad Sayyidus Shaleh Yofa, Adnan Fauzi · 2021
Network infrastructure requires constant monitoring over time, including identifying problems. Generally, an experienced network administrator responsible for the entire network is doing this task, which is inefficient because an administrator does not have full 24-hour availability in providing a fast and proper response at the time of the ongoing attack. Network attack identification systems are built to help solve this problem. This study focuses on identifying network attacks, namely Denial of Service attacks, by implementing the Dynamic Thresholding method. The data used for this research are the DARPA 2000 dataset and the self-generated dataset in a controlled laboratory environment, with the Netflow protocol and the Elasticsearch search engine. The results of the implementation show a lower False-Positive Rate in the DARPA 2000 dataset (33.33%) and the generated dataset (50%) in comparison with the False-Positive Rate value on the original paper (98%).