DDoS Attack Forensics Pattern Identification using Entropy and Hurst Coefficient based Fusion Model
Meghana Solanki, Sangita Santosh Chaudhari · 2023
Distributed Denial of Service (DDoS) is a very common network attack that involves the continuous flooding of request packets from adversaries to clog the network servers. An offense committed against a system’s network services can be prosecuted in court using network forensics, and the adversaries will face legal repercussions. A wide variety of pattern analysis and deep learning models are proposed by researchers to identify DDoS attacks. But most of them are highly complex or cannot be applied to real-time traffic which limits overall scalability and applicability. To overcome these issues, this text proposes the design of a novel fusion model for the identification of DDoS attacks via entropically analyzing Hurst coefficients. The model initially estimates Hurst coefficients from real-time traffic to get an estimate of attack packets. The traffic is also processed via an entropy estimation block, which assists in shortlisting DDoS attack packets. The attack packets identified from Hurst coefficients are revalidated via entropy analysis, while the packets from entropy analysis are revalidated via Hurst coefficients. Due to this cross-validation, the model is able to identify DDoS attack packets with higher accuracy when compared with individual models. To validate this claim, the proposed FMDAEHC Model was evaluated on multiple DDoS datasets, and parametric analysis was done in terms of accuracy, precision, recall, and delay metrics. Based on this analysis it was observed that the proposed model was able to achieve 99.75% accuracy, with a low delay which makes it useful for high-performance network deployments. This performance was also compared with various state-of-the-art models. It was observed that the proposed model was 5.5% more accurate, 5.4% more precise, 16.1% faster, and achieved a 5.1% better recall than existing models. Due to this, the proposed model is useful for multiple network scenarios.