Denial-of-Service Attack Detection via Differential Analysis of Generalized Entropy Progressions

09/17/2021
by   Omer Subasi, et al.
0

Denial-of-Service (DoS) attacks are one the most common and consequential cyber attacks in computer networks. While existing research offers a plethora of detection methods, the issue of achieving both scalability and high detection accuracy remains open. In this work, we address this problem by developing a differential method based on generalized entropy progression. In this method, we continuously fit the line of best fit to the entropy progression and check if the derivative, that is, the slope of this line is less than the negative of the dynamically computed standard deviation of the derivatives. As a result, we omit the usage of the thresholds and the results with five real-world network traffic datasets confirm that our method outperforms threshold-based DoS attack detection by two orders of magnitude on average. Our method achieves false positive rates that are up to 7 arithmetic mean is 3 network flow. Moreover, since the main computation cost of our method is the entropy computation, which is linear in the volume of the unit-time network flow and it uses integer only operations and a small fraction of the total flow, it is therefore lightweight and scalable.

READ FULL TEXT
research
03/19/2019

DDoS attack detection method based on feature extraction of deep belief network

Distributed Denial of Service (DDOS) attack is one of the most common ne...
research
08/26/2019

SynGAN: Towards Generating Synthetic Network Attacks using GANs

The rapid digital transformation without security considerations has res...
research
06/19/2019

A Novel DDoS Attack Detection Method Using Optimized Generalized Multiple Kernel Learning

Distributed Denial of Service (DDoS) attack has become one of the most d...
research
03/28/2019

DDoS Attack Detection Method Based on Network Abnormal Behavior in Big Data Environment

Distributed denial of service (DDoS) attack becomes a rapidly growing pr...
research
04/11/2021

Tracking Normalized Network Traffic Entropy to Detect DDoS Attacks in P4

Distributed Denial-of-Service (DDoS) attacks represent a persistent thre...
research
11/08/2018

A practical approach to detection of distributed denial-of-service attacks using a hybrid detection method

This paper presents a hybrid method for the detection of distributed den...
research
07/02/2019

Efficient Cyber Attacks Detection in Industrial Control Systems Using Lightweight Neural Networks

Industrial control systems (ICSs) are widely used and vital to industry ...

Please sign up or login with your details

Forgot password? Click here to reset