(A) proactive detection method of DDoS attack using cluster analysis군집분석을 사용한 DDoS 공격의 사전 탐지 방법에 관한 연구

Cited 0 time in webofscience Cited 0 time in scopus
  • Hit : 550
  • Download : 0
Distributed Denial of Service (DDoS) attacks can easily exhaust the computing and communication resources of their victim within short period of time and they deteriorate the performance of whole network as well as interrupt communication of a specific host. Therefore we propose a method for proactive detection of DDoS attacks in this paper. DDoS attacks go on with several steps. We look into these features of DDoS attacks in order to detect precursors of DDoS attacks and then select variables based on the features. After that, we perform cluster analysis for proactive detection of DDoS attacks. We experimented with 2000 DARPA Intrusion Detection Scenario Specific Data Set in order to evaluate our method. In result, the data set is divided into several detailed groups and we can analyze the network traffic of each group according to the feature of each phase. With our proposed method, we can know not only whether incoming traffic is normal or abnormal but also which phase incoming traffic corresponds to. Therefore we can detect DDoS attacks proactively. As our method needs only normalized distance in order to determine which group incoming traffic belongs to, it is very easy to implement. For this reason, our method is proper for real-time detection.
Advisors
Kim, Se-Hunresearcher김세헌researcher
Description
한국과학기술원 : 산업공학과,
Publisher
한국과학기술원
Issue Date
2006
Identifier
255382/325007  / 020043143
Language
eng
Description

학위논문(석사) - 한국과학기술원 : 산업공학과, 2006.2, [ iii, 43 p. ]

Keywords

phase; proactive detection; cluster analsis; Ddos attack; real-time detection; 실시간 탐지; 단계; 사전 탐지; 군집 분석; Ddos 공격

URI
http://hdl.handle.net/10203/40730
Link
http://library.kaist.ac.kr/search/detail/view.do?bibCtrlNo=255382&flag=dissertation
Appears in Collection
IE-Theses_Master(석사논문)
Files in This Item
There are no files associated with this item.

qr_code

  • mendeley

    citeulike


rss_1.0 rss_2.0 atom_1.0