Deakin University
Browse

File(s) under permanent embargo

ERM: an accurate approach to detect DDoS attacks using entropy rate measurement

journal contribution
posted on 2019-10-01, 00:00 authored by Lu Zhou, Keshav SoodKeshav Sood, Yong XiangYong Xiang
The challenges from Distributed Denial-of-Service (DDoS) attacks are severe and still increasing significantly. We observe that the existing entropy-based methods only consider the probability distribution of traffic flows that have high false negative rates. On the other hand, sophisticated attack strategies, increasing attack strength and dynamic nature of network traffic patterns make it more difficult to detect the DDoS attacks with high accuracy. In this letter, we present an accurate approach, entropy rate measurement (ERM), to detect DDoS attacks. The proposed approach is based on the differences between the probability distributions and the number of flows. Both theoretical proofs and the results of experiments using real datasets demonstrate that our method has high detection accuracy rate compared to the existing measurements.

History

Journal

IEEE Communications Letters

Volume

23

Issue

10

Pagination

1700 - 1703

Publisher

IEEE

Location

Piscataway, N.J.

ISSN

1089-7798

eISSN

1558-2558

Language

eng

Publication classification

C1 Refereed article in a scholarly journal