• KSII Transactions on Internet and Information Systems
    Monthly Online Journal (eISSN: 1976-7277)

Combining Adaptive Filtering and IF Flows to Detect DDoS Attacks within a Router


Abstract

Traffic matrix-based anomaly detection and DDoS attacks detection in networks are research focus in the network security and traffic measurement community. In this paper, firstly, a new type of unidirectional flow called IF flow is proposed. Merits and features of IF flows are analyzed in detail and then two efficient methods are introduced in our DDoS attacks detection and evaluation scheme. The first method uses residual variance ratio to detect DDoS attacks after Recursive Least Square (RLS) filter is applied to predict IF flows. The second method uses generalized likelihood ratio (GLR) statistical test to detect DDoS attacks after a Kalman filter is applied to estimate IF flows. Based on the two complementary methods, an evaluation formula is proposed to assess the seriousness of current DDoS attacks on router ports. Furthermore, the sensitivity of three types of traffic (IF flow, input link and output link) to DDoS attacks is analyzed and compared. Experiments show that IF flow has more power to expose anomaly than the other two types of traffic. Finally, two proposed methods are compared in terms of detection rate, processing speed, etc., and also compared in detail with Principal Component Analysis (PCA) and Cumulative Sum (CUSUM) methods. The results demonstrate that adaptive filter methods have higher detection rate, lower false alarm rate and smaller detection lag time.


Statistics

Show / Hide Statistics

Statistics (Cumulative Counts from December 1st, 2015)
Multiple requests among the same browser session are counted as one view.
If you mouse over a chart, the values of data points will be shown.


Cite this article

[IEEE Style]
R. Yan, Q. Zheng, H. Li, "Combining Adaptive Filtering and IF Flows to Detect DDoS Attacks within a Router," KSII Transactions on Internet and Information Systems, vol. 4, no. 3, pp. 428-451, 2010. DOI: 10.3837/tiis.2010.06.014.

[ACM Style]
Ruoyu Yan, Qinghua Zheng, and Haifei Li. 2010. Combining Adaptive Filtering and IF Flows to Detect DDoS Attacks within a Router. KSII Transactions on Internet and Information Systems, 4, 3, (2010), 428-451. DOI: 10.3837/tiis.2010.06.014.

[BibTeX Style]
@article{tiis:19866, title="Combining Adaptive Filtering and IF Flows to Detect DDoS Attacks within a Router", author="Ruoyu Yan and Qinghua Zheng and Haifei Li and ", journal="KSII Transactions on Internet and Information Systems", DOI={10.3837/tiis.2010.06.014}, volume={4}, number={3}, year="2010", month={June}, pages={428-451}}