学位论文详细信息
Monitoring unknown source IP addresses and packet sizes to detect DDoS attacks
Poisson Cluster Process;Compound Pareto Distribution;Binary Hypothesis Testing;Sequential Detection;Distributed Denial of Service (DDoS) Attacks
Kone, Roseline
关键词: Poisson Cluster Process;    Compound Pareto Distribution;    Binary Hypothesis Testing;    Sequential Detection;    Distributed Denial of Service (DDoS) Attacks;   
Others  :  https://www.ideals.illinois.edu/bitstream/handle/2142/49735/Roseline_Kone.pdf?sequence=1&isAllowed=y
美国|英语
来源: The Illinois Digital Environment for Access to Learning and Scholarship
PDF
【 摘 要 】

This thesis presents three procedures to detect Distributed Denial of Service (DDoS) attacks. DDoSattacks are known as one of the most expensive and destructive Internet threats. Assuming networktra c is a marked Poisson process, two parametric detection models are developed. The arrivalof packet ows is modeled as Poisson process with cluster sizes that follows a mixture of discreteand heavy tailed distributions. Both detection systems monitor the percentage of unknown sourceIP addresses. Therst detection model is formulated as axed sample size binary hypothesistesting. The decision making is based on the Neyman-Pearson criteria. The second parametricmodel is a sequential probability ratio test where the sample size is a random variable. Acceptanceand rejection boundaries are deduced based on Wald's Fundamental Identity. Given that parametricdistributions may fail to capture the complex and dynamic nature of the Internet, a thirdnon-parametric detection model is proposed. In addition to the percentage of unknown source IPaddresses, a second test statistic is introduced. The latter represents the mean to standard deviationratio of data packet sizes. The Neyman-Pearson threshold is estimated from the empiricaldistribution functions of both random variables.

【 预 览 】
附件列表
Files Size Format View
Monitoring unknown source IP addresses and packet sizes to detect DDoS attacks 1860KB PDF download
  文献评价指标  
  下载次数:4次 浏览次数:16次