ISSN 0974 - 9330 (Online); 0975 - 2307 (Print)
http://airccse.org/journal/ijnsa.html
A Hybrid Approach Combining Rule-Based and Anomaly-Based Detection Against DDoS Attacks
ABSTRACT
We have designed a hybrid approach combining rule-based and anomaly-based detection against DDoS attacks. In the approach, the rule-based detection has established a set of rules and the anomaly-based detection use one-way ANOVA test to detect possible attacks. We adopt TFN2K (Tribe Flood, the Net 2K) as an attack traffic generator and monitor the system resource of the victim like throughput, memory utilization, CPU utilization consumed by attack traffic. Target users of the proposed scheme are data center administrators. The types of attack traffic have been analysed and by that we develop a defense scheme. The experiment has demonstrated that the proposed scheme can effectively detect the attack traffic.
KEYWORDS
Distributed denial of service, firewall, detection
For more details: http://aircconline.com/ijnsa/V8N5/8516ijnsa01.pdf
No comments:
Post a Comment