Reliably Identifying Signs of DDOS Flood Attacks Based on Traffic Pattern Recognition
Ming Li · 2022
This chapter expounds an approach of reliable identification of long-range-dependent traffic under distributed denial-of-service attacks. For such a type of intrusion detection systems, the key point is to design a system such that it has high identification/detection probability, low false alarm probability, and low miss probability. This chapter gives a statistical detection scheme based on identifying abnormal variations of long-range-dependent traffic time series. The representations of three probability distributions mentioned above are given and a decision-making region is explained. With this region, one can know what an identification (or false alarm or miss) probability is for capturing signs of distributed denial-of-service flood attacks. The significance of a decision-making region is that it provides a guideline to set appropriate threshold value so as to assure pre-determined high identification probability, pre-desired low false alarm probability, and pre-determined low miss probability. A case study is demonstrated.