41
Views
0
CrossRef citations to date
0
Altmetric
Original Articles

An abnormal‐based approach to effectively detect DDoS attacks

&
Pages 889-895 | Received 31 May 2009, Accepted 15 Oct 2009, Published online: 04 Mar 2011
 

Abstract

Distributed Denail‐of‐Service (DDoS) attacks are a serious threat to the safety and security of cyberspace. In this paper we propose a novel metric to detect DDoS attacks in the Internet. More precisely, we use the function of order α of the generalized (Rényi) entropy to distinguish DDoS attacks traffic from legitimate network traffic effectively. In information theory, entropies make up the basis for distance and divergence measures among various probability densities. We design our abnormal‐based detection metric using the generalized entropy. The experimental results show that our proposed approach can not only detect DDoS attacks early (it can detect attacks one hop earlier than using the Shannon metric while order α = 2, and two hops earlier than the Shannon metric while order α = 10.) but can also reduce both the false positive rate and the false negative rate, compared with the traditional Shannon entropy metric approach.

Notes

Corresponding author. (Tel: +61–3–92517603; Fax: +61–3–92517604; Email: {ktql, wanlei}@deakin.edu.au)

Reprints and Corporate Permissions

Please note: Selecting permissions does not provide access to the full text of the article, please see our help page How do I view content?

To request a reprint or corporate permissions for this article, please click on the relevant link below:

Academic Permissions

Please note: Selecting permissions does not provide access to the full text of the article, please see our help page How do I view content?

Obtain permissions instantly via Rightslink by clicking on the button below:

If you are unable to obtain permissions via Rightslink, please complete and submit this Permissions form. For more information, please visit our Permissions help page.