Attack simulation and signature extraction of low-rate DDoS
LDDoS (low-rate distributed denial-of-service) was a new type of DDoS attack. It had small traffic and cov- ered by normal network traffic. LDDoS attack was so stealthy that the detection and defense approaches of traditional DDoS could not be effective. Experiments show that LDDoS attack traffic ex...
Saved in:
Main Authors: | , |
---|---|
Format: | Article |
Language: | zho |
Published: |
Editorial Department of Journal on Communications
2008-01-01
|
Series: | Tongxin xuebao |
Subjects: | |
Online Access: | http://www.joconline.com.cn/zh/article/74655676/ |
Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
_version_ | 1841537445906087936 |
---|---|
author | WU Zhi-jun ZHANG Dong |
author_facet | WU Zhi-jun ZHANG Dong |
author_sort | WU Zhi-jun |
collection | DOAJ |
description | LDDoS (low-rate distributed denial-of-service) was a new type of DDoS attack. It had small traffic and cov- ered by normal network traffic. LDDoS attack was so stealthy that the detection and defense approaches of traditional DDoS could not be effective. Experiments show that LDDoS attack traffic exhibit strong periodicity. Based on the periodical feature of LDDoS attack, the signatures of LDDoS attack are extracted through analyzing the cache queue of target router for the purpose of detection and defense of LDDoS attack. Statistics on the percentage of normal and attack flow in total traffic show that LDDoS attack has two signatures. Experiments on the two signatures in NS-2 platform have been conducted to detect LDDoS attack, tests result show that the extracted two signatures can reduce false positives of LDDoS attack detection schemes. |
format | Article |
id | doaj-art-4ddccf72edb24f62a74438b795c62b4e |
institution | Kabale University |
issn | 1000-436X |
language | zho |
publishDate | 2008-01-01 |
publisher | Editorial Department of Journal on Communications |
record_format | Article |
series | Tongxin xuebao |
spelling | doaj-art-4ddccf72edb24f62a74438b795c62b4e2025-01-14T08:34:01ZzhoEditorial Department of Journal on CommunicationsTongxin xuebao1000-436X2008-01-01717674655676Attack simulation and signature extraction of low-rate DDoSWU Zhi-junZHANG DongLDDoS (low-rate distributed denial-of-service) was a new type of DDoS attack. It had small traffic and cov- ered by normal network traffic. LDDoS attack was so stealthy that the detection and defense approaches of traditional DDoS could not be effective. Experiments show that LDDoS attack traffic exhibit strong periodicity. Based on the periodical feature of LDDoS attack, the signatures of LDDoS attack are extracted through analyzing the cache queue of target router for the purpose of detection and defense of LDDoS attack. Statistics on the percentage of normal and attack flow in total traffic show that LDDoS attack has two signatures. Experiments on the two signatures in NS-2 platform have been conducted to detect LDDoS attack, tests result show that the extracted two signatures can reduce false positives of LDDoS attack detection schemes.http://www.joconline.com.cn/zh/article/74655676/LDDoSsignaturepercentage of flow |
spellingShingle | WU Zhi-jun ZHANG Dong Attack simulation and signature extraction of low-rate DDoS Tongxin xuebao LDDoS signature percentage of flow |
title | Attack simulation and signature extraction of low-rate DDoS |
title_full | Attack simulation and signature extraction of low-rate DDoS |
title_fullStr | Attack simulation and signature extraction of low-rate DDoS |
title_full_unstemmed | Attack simulation and signature extraction of low-rate DDoS |
title_short | Attack simulation and signature extraction of low-rate DDoS |
title_sort | attack simulation and signature extraction of low rate ddos |
topic | LDDoS signature percentage of flow |
url | http://www.joconline.com.cn/zh/article/74655676/ |
work_keys_str_mv | AT wuzhijun attacksimulationandsignatureextractionoflowrateddos AT zhangdong attacksimulationandsignatureextractionoflowrateddos |