Two-Level Detection Method of DDoS Attack Mimicking CDN Caches
Kazuya Taniguchi, Noriaki Kamiyama · 2025
Distributed Denial of Service (DDoS) attacks have become increasingly frequent, overwhelming target servers by flooding them with packets from bots. Though firewalls can block illegitimate traffic, attacks become harder to detect when bots spoof the IP addresses of trusted content delivery network (CDN) cache servers. To mitigate this, we propose a two-stage detection method that uses a dynamic based on packet arrival intervals and DNS $\log$ analysis. By incorporating Z-scores, our method adapts to changing traffic patterns and significantly reduces the load on the origin server (OS). Performance evaluations show that our approach enhances DDoS detection accuracy while lowering processing costs, with optimal thresholds designed for varying environments.