Attack simulation and signature extraction of low-rate DDoS

LDDoS (low-rate distributed denial-of-service) was a new type of DDoS attack. It had small traffic and cov- ered by normal network traffic. LDDoS attack was so stealthy that the detection and defense approaches of traditional DDoS could not be effective. Experiments show that LDDoS attack traffic ex...

Full description

Saved in:
Bibliographic Details
Main Authors: WU Zhi-jun, ZHANG Dong
Format: Article
Language:zho
Published: Editorial Department of Journal on Communications 2008-01-01
Series:Tongxin xuebao
Subjects:
Online Access:http://www.joconline.com.cn/zh/article/74655676/
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1841537445906087936
author WU Zhi-jun
ZHANG Dong
author_facet WU Zhi-jun
ZHANG Dong
author_sort WU Zhi-jun
collection DOAJ
description LDDoS (low-rate distributed denial-of-service) was a new type of DDoS attack. It had small traffic and cov- ered by normal network traffic. LDDoS attack was so stealthy that the detection and defense approaches of traditional DDoS could not be effective. Experiments show that LDDoS attack traffic exhibit strong periodicity. Based on the periodical feature of LDDoS attack, the signatures of LDDoS attack are extracted through analyzing the cache queue of target router for the purpose of detection and defense of LDDoS attack. Statistics on the percentage of normal and attack flow in total traffic show that LDDoS attack has two signatures. Experiments on the two signatures in NS-2 platform have been conducted to detect LDDoS attack, tests result show that the extracted two signatures can reduce false positives of LDDoS attack detection schemes.
format Article
id doaj-art-4ddccf72edb24f62a74438b795c62b4e
institution Kabale University
issn 1000-436X
language zho
publishDate 2008-01-01
publisher Editorial Department of Journal on Communications
record_format Article
series Tongxin xuebao
spelling doaj-art-4ddccf72edb24f62a74438b795c62b4e2025-01-14T08:34:01ZzhoEditorial Department of Journal on CommunicationsTongxin xuebao1000-436X2008-01-01717674655676Attack simulation and signature extraction of low-rate DDoSWU Zhi-junZHANG DongLDDoS (low-rate distributed denial-of-service) was a new type of DDoS attack. It had small traffic and cov- ered by normal network traffic. LDDoS attack was so stealthy that the detection and defense approaches of traditional DDoS could not be effective. Experiments show that LDDoS attack traffic exhibit strong periodicity. Based on the periodical feature of LDDoS attack, the signatures of LDDoS attack are extracted through analyzing the cache queue of target router for the purpose of detection and defense of LDDoS attack. Statistics on the percentage of normal and attack flow in total traffic show that LDDoS attack has two signatures. Experiments on the two signatures in NS-2 platform have been conducted to detect LDDoS attack, tests result show that the extracted two signatures can reduce false positives of LDDoS attack detection schemes.http://www.joconline.com.cn/zh/article/74655676/LDDoSsignaturepercentage of flow
spellingShingle WU Zhi-jun
ZHANG Dong
Attack simulation and signature extraction of low-rate DDoS
Tongxin xuebao
LDDoS
signature
percentage of flow
title Attack simulation and signature extraction of low-rate DDoS
title_full Attack simulation and signature extraction of low-rate DDoS
title_fullStr Attack simulation and signature extraction of low-rate DDoS
title_full_unstemmed Attack simulation and signature extraction of low-rate DDoS
title_short Attack simulation and signature extraction of low-rate DDoS
title_sort attack simulation and signature extraction of low rate ddos
topic LDDoS
signature
percentage of flow
url http://www.joconline.com.cn/zh/article/74655676/
work_keys_str_mv AT wuzhijun attacksimulationandsignatureextractionoflowrateddos
AT zhangdong attacksimulationandsignatureextractionoflowrateddos