Early DDoS Alerts Based on Optimal Sub-OD Pairs and Markov Model
Wenyue Sun, Qinbao Xu, Changda Wang · 2024
Detecting Distributed Denial of Service (DDoS) attacks effectively has long been a challenge due to their disruptive nature. As the amount of network traffic increases, artificial intelligence based methods for detecting DDoS attacks have faced challenges of lower efficiency due to model training. On that account, a DDoS alerting method based on optimal sub-OD (Origin-Destination) pairs and Markov model (SODMM) is devised. SODMM first designs a subset feature evaluation technique to identify the most informative OD pairs, subsequently forming a TM based on these pairs. Then, the Generalized Network Temperature (GNT) derived from the TM is used to define the state transition matrix of a Markov model, dynamically adjusting such a transition matrix to enhance the accuracy of DDoS attack predictions. Experimental results show that SODMM outperforms the GNT, NAEW-GNT, and Rényi-GNT methods in terms of early alerts, possessing the highest ACC of 95.6%, as well as the lowest FPR of 10.06% and FNR of 3.83%.