Facilitating DoS Attack Detection using Unsupervised Anomaly Detection

Christos Bellas, Georgia Kougka, Athanasios Naskos, Anastasios Gounaris, Athena I. Vakali, Christos Xenakis, Apostolos N. Papadopoulos · 2022

Modern techniques in intrusion and DoS (Denial of Service) detection tend to be either supervised or semi-supervised, i.e., they require training and labelled data. In this work, we study the problem of correlating security attacks with anomalies reported at runtime by a fully unsupervised outlier detection module, i.e., a component that does not require any training at all. Through a concrete proof-of-concept case study, we demonstrate that unsupervised anomaly detection is both efficient and effective, but still, it needs to be combined with additional mechanisms to yield a complete intrusion detection and prevention solution.

Read the paper · More papers on PaperTik