透過您的圖書館登入
IP:18.219.189.247
  • 會議論文

使用統計方法之常態分配來偵測分散式阻斷服務攻擊

Detecting Distributed Denial-of-Service Attacks by Using Statistical Analysis of Normal Distribution

摘要


本研究提出一個基於抵達率的統計量之新的偵察DoS攻擊的方法。我們首先研究正常封包的抵達率統計量。再者,分析結果顯示正常封包的抵達率符合常態分配。因此,我們將透過最大抵達率建立門檻值以作為偵察DoS的流量。在我們的實驗結果顯示主動錯誤率及被動錯誤率二者皆很小。因此,證明本研究所提出的機制能快速又精確的偵察DoS攻擊。

並列摘要


This study proposed a new detection method for DoS attack traffic based on the statistics of arrival rate. We first investigate the statistics of arrival rates of normal packets. Our analytical results show that the arrival rate of normal packets can be can be modeled by normal distribution. We then set up a threshold for maximum arrival rate to detect DoS flood traffic. The experiment results show that the possibilities of both false positives and false negatives are very low. The proposed mechanism is demonstrated to have the capability of detecting DoS attack quickly and accurately.

延伸閱讀