Chapter

Frontiers in Algorithmics

Volume 5598 of the series Lecture Notes in Computer Science pp 207-215

DDoS Attack Detection Algorithm Using IP Address Features

  • Jieren ChengAffiliated withSchool of Computer, National University of Defense TechnologyDepartment of mathematics, Xiangnan University
  • , Jianping YinAffiliated withSchool of Computer, National University of Defense Technology
  • , Yun LiuAffiliated withSchool of Computer, National University of Defense Technology
  • , Zhiping CaiAffiliated withSchool of Computer, National University of Defense Technology
  • , Min LiAffiliated withSchool of Computer, National University of Defense Technology

Abstract

Distributed denial of service (DDoS) attack is one of the major threats to the current Internet. After analyzing the characteristics of DDoS attacks and the existing Algorithms to detect DDoS attacks, this paper proposes a novel detecting algorithm for DDoS attacks based on IP address features value (IAFV). IAFV is designed to reflect the essential DDoS attacks characteristics, such as the abrupt traffic change, flow dissymmetry, distributed source IP addresses and concentrated target IP addresses. IAFV time series can be used to characterize the essential change features of network flows. Furthermore, a trained support vector machine (SVM) classifier is applied to identify the DDoS attacks. The experimental results on the MIT data set show that our algorithm can detect DDoS attacks accurately and reduce the false alarm rate drastically.

Keywords

network security distributed denial of service attack IP address features value support vector machine