Network Traffic Anomaly Detection: A Powerful Tool for DDoS Attack Identification

D. Balakrishnan, Umasree Mariappan, T.Blessing Karunya, M. Punitha Shri, Harini S S, R. HarishKrishna · 2024

Distributed Denial-of-Service (DDoS) attacks pose a significant threat to network security and service availability. Traditional detection methods often struggle to differentiate between legitimate traffic and malicious attacks. This work explores the potential of network traffic anomaly detection for accurate DDoS attack identification. We propose a novel approach utilizing a hybrid ARIMA-SWGARCH model. The ARIMA component effectively captures the inherent seasonality and trends within network traffic data, while the SWGARCH component models the volatility clustering often observed during DDoS attacks. By analyzing the residuals of the ARIMA model with the SWGARCH framework, we aim to identify significant deviations indicative of DDoS activity. This hybrid model offers several advantages over existing methods, including improved accuracy, adaptability to varying traffic patterns, and the ability to capture both level and volatility changes in traffic flow. The effectiveness of the proposed approach is evaluated using real-world network traffic datasets, demonstrating its potential as a powerful tool for DDoS attack identification.

Read the paper · More papers on PaperTik