Conference Papers Year : 2014

Early DDoS Detection Based on Data Mining Techniques

Abstract

In the past few years, internet has experienced a rapid growth in users and services. This led to an increase of different type of cyber-crimes. One of the most important is the Distributed Denial of Service (DDoS) attack, which someone can unleash through many different isolated hosts and make a system to shut down due to resources exhaustion. The importance of the problem can be easily identified due to the huge number of references found in literature trying to detect and prevent such attacks. In the current paper, a novel method based on a data mining technique is introduced in order to early warn the network administrator of a potential DDoS attack. The method uses the advanced All Repeated Patterns Detection (ARPaD) Algorithm, which allows the detection of all repeated patterns in a sequence. The proposed method can give very fast results regarding all IP prefixes in a sequence of hits and, therefore, warn the network administrator if a potential DDoS attack is under development. Based on several experiments conducted, it has been proven experimentally the importance of the method for the detection of a DDoS attack since it can detect a potential DDoS attack at the beginning and before it affects the system.
Fichier principal
Vignette du fichier
978-3-662-43826-8_15_Chapter.pdf (126.32 Ko) Télécharger le fichier
Origin Files produced by the author(s)
Loading...

Dates and versions

hal-01400941 , version 1 (22-11-2016)

Licence

Identifiers

Cite

Konstantinos Xylogiannopoulos, Panagiotis Karampelas, Reda Alhajj. Early DDoS Detection Based on Data Mining Techniques. 8th IFIP International Workshop on Information Security Theory and Practice (WISTP), Jun 2014, Heraklion, Crete, Greece. pp.190-199, ⟨10.1007/978-3-662-43826-8_15⟩. ⟨hal-01400941⟩
729 View
518 Download

Altmetric

Share

More