EARLY DETECTION AND DEFENSE METHODS FOR VARIABLE DDOS ATTACKS BASED ON PACKET GROUP PROCESSING ANALYSIS

Петро ПОНОЧОВНИЙ, І. С. Іванченко · Scientific Notes of the State University of Telecommunications · 2024

Early detection and defense methods for variable ddos attacks based on packet group processing analysis.This paper proposes a method for early detection and defense of variable DDoS attacks based on packet group processing analysis.The method combines real-time traffic analysis and machine learning to detect anomalies in network data behavior.This enables a quick response to changes in the attack vector and guarantees the stability and security of the information system.The effectiveness of the method is confirmed by experimental studies that demonstrate the accuracy of detection and minimization of delays in network operations.The method is based on dividing network traffic into groups of packets and analyzing them taking into account their statistical, temporal and behavioral characteristics.Particular attention is paid to the use of machine learning algorithms to detect deviations in traffic patterns characteristic of DDoS attacks.The proposed approach makes it possible to detect the signs of an attack at an early stage, before the impact of the attack becomes fatal for the infrastructure.This paper describes an algorithm for processing packet swarms that takes into account the variability of attacks and adapts to new attacker methods.The computational efficiency of the method is also discussed, which is important to ensure its practical application on heavily loaded systems.To evaluate the effectiveness of the method, a series of experiments were performed on real and synthetic datasets, achieving high attack detection accuracy (>95%) and a low level of false positives.The application of the developed method not only provides effective protection against the latest DDoS attacks, but also minimizes the risk of financial loss and reputational damage associated with their consequences.The research results can be integrated into existing defense systems to increase their adaptability and resilience to cyber threats.

Read the paper · More papers on PaperTik