期刊文献+

Detecting DDoS Attacks against Web Server Using Time Series Analysis 被引量:1

Detecting DDoS Attacks against Web Server Using Time Series Analysis
下载PDF
导出
摘要 Distributed Denial of Service (DDoS) attack is a major threat to the availability of Web service. The inherent presence of self-similarity in Web traffic motivates the applicability of time series analysis in the study of the burst feature of DDoS attack. This paper presents a method of detecting DDoS attacks against Web server by analyzing the abrupt change of time series data obtained from Web traffic. Time series data are specified in reference sliding window and test sliding window, and the abrupt change is modeled using Auto-Regressive (AR) process. By comparing two adjacent nonoverlapping windows of the time series, the attack traffic could be detected at a time point. Combined with alarm correlation and location correlation, not only the presence of DDoS attack, but also its occurring time and location can be deter mined. The experimental results in a test environment are illustrated to justify our method. Distributed Denial of Service (DDoS) attack is a major threat to the availability of Web service. The inherent presence of self-similarity in Web traffic motivates the applicability of time series analysis in the study of the burst feature of DDoS attack. This paper presents a method of detecting DDoS attacks against Web server by analyzing the abrupt change of time series data obtained from Web traffic. Time series data are specified in reference sliding window and test sliding window, and the abrupt change is modeled using Auto-Regressive (AR) process. By comparing two adjacent nonoverlapping windows of the time series, the attack traffic could be detected at a time point. Combined with alarm correlation and location correlation, not only the presence of DDoS attack, but also its occurring time and location can be deter mined. The experimental results in a test environment are illustrated to justify our method.
出处 《Wuhan University Journal of Natural Sciences》 EI CAS 2006年第1期175-180,共6页 武汉大学学报(自然科学英文版)
基金 Supported by the National Natural Science Funda-tion of China (60373075)
关键词 distributed denial of service auto-regressive model time series Web server distributed denial of service auto-regressive model time series Web server
  • 相关文献

参考文献5

  • 1Jo?o B. D. Cabrera,Lundy Lewis,Xinzhou Qin,Wenke Lee,Raman K. Mehra.Proactive Intrusion Detection and Distributed Denial of Service Attacks—A Case Study in Security Management[J].Journal of Network and Systems Management.2002(2) 被引量:1
  • 2Peter J B,Richard A D.Time Series : Theoryand Methods[]..2001 被引量:1
  • 3Mark E C,Azer B.Self-Si milarityin World Wide Web Traf- fic :Evidence and Possible Causes[].IEEE/ ACMTransactions on Networking.1997 被引量:1
  • 4Garber L.Denial-of-Service Attacks Rip the Internet[].IEEE Computer.2000 被引量:1
  • 5Chao CS,Yang D L,Liu AC.ALANFault Diagnosis Sys- tem[].Computer Communications.2001 被引量:1

引证文献1

二级引证文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部