The Experts below are selected from a list of 17907 Experts worldwide ranked by ideXlab platform

Wanlei Zhou - One of the best experts on this subject based on the ideXlab platform.

  • Distributed Denial of Service (DDoS) detection by Traffic pattern analysis
    Peer-to-Peer Networking and Applications, 2014
    Co-Authors: Theerasak Thapngam, Wanlei Zhou, Shui Yu, S. Kami Makki
    Abstract:

    In this paper, we propose a behavior-based detection that can discriminate Distributed Denial of Service (DDoS) Attack Traffic from legitimated Traffic regardless to various types of the Attack packets and methods. Current DDoS Attacks are carried out by Attack tools, worms and botnets using different packet-transmission rates and packet forms to beat defense systems. These various Attack strategies lead to defense systems requiring various detection methods in order to identify the Attacks. Moreover, DDoS Attacks can craft the Traffics like flash crowd events and fly under the radar through the victim. We notice that DDoS Attacks have features of repeatable patterns which are different from legitimate flash crowd Traffics. In this paper, we propose a comparable detection methods based on the Pearson’s correlation coefficient. Our methods can extract the repeatable features from the packet arrivals in the DDoS Traffics but not in flash crowd Traffics. The extensive simulations were tested for the optimization of the detection methods. We then performed experiments with several datasets and our results affirm that the proposed methods can differentiate DDoS Attacks from legitimate Traffics.

  • cloud security defence to protect cloud computing against http dos and xml dos Attacks
    Journal of Network and Computer Applications, 2011
    Co-Authors: Ashley Chonka, Wanlei Zhou, Yang Xiang, Alessio Bonti
    Abstract:

    Cloud computing is still in its infancy in regards to its software as services (SAS), web services, utility computing and platform as services (PAS). All of these have remained individualized systems that you still need to plug into, even though these systems are heading towards full integration. One of the most serious threats to cloud computing itself comes from HTTP Denial of Service or XML-Based Denial of Service Attacks. These types of Attacks are simple and easy to implement by the Attacker, but to security experts they are twice as difficult to stop. In this paper, we recreate some of the current Attacks that Attackers may initiate as HTTP and XML. We also offer a solution to traceback through our Cloud TraceBack (CTB) to find the source of these Attacks, and introduce the use of a back propagation neutral network, called Cloud Protector, which was trained to detect and filter such Attack Traffic. Our results show that we were able to detect and filter most of the Attack messages and were able to identify the source of the Attack within a short period of time.

  • low rate ddos Attacks detection and traceback by using new information metrics
    IEEE Transactions on Information Forensics and Security, 2011
    Co-Authors: Yang Xiang, Wanlei Zhou
    Abstract:

    A low-rate distributed denial of service (DDoS) Attack has significant ability of concealing its Traffic because it is very much like normal Traffic. It has the capacity to elude the current anomaly-based detection schemes. An information metric can quantify the differences of network Traffic with various probability distributions. In this paper, we innovatively propose using two new information metrics such as the generalized entropy metric and the information distance metric to detect low-rate DDoS Attacks by measuring the difference between legitimate Traffic and Attack Traffic. The proposed generalized entropy metric can detect Attacks several hops earlier (three hops earlier while the order α = 10 ) than the traditional Shannon metric. The proposed information distance metric outperforms (six hops earlier while the order α = 10) the popular Kullback-Leibler divergence approach as it can clearly enlarge the adjudication distance and then obtain the optimal detection sensitivity. The experimental results show that the proposed information metrics can effectively detect low-rate DDoS Attacks and clearly reduce the false positive rate. Furthermore, the proposed IP traceback algorithm can find all Attacks as well as Attackers from their own local area networks (LANs) and discard Attack Traffic.

  • discriminating ddos Attack Traffic from flash crowd through packet arrival patterns
    Conference on Computer Communications Workshops, 2011
    Co-Authors: Theerasak Thapngam, Wanlei Zhou, Gleb Beliakov
    Abstract:

    Current DDoS Attacks are carried out by Attack tools, worms and botnets using different packet-transmission strategies and various forms of Attack packets to beat defense systems. These problems lead to defense systems requiring various detection methods in order to identify Attacks. Moreover, DDoS Attacks can mix their Traffics during flash crowds. By doing this, the complex defense system cannot detect the Attack Traffic in time. In this paper, we propose a behavior based detection that can discriminate DDoS Attack Traffic from Traffic generated by real users. By using Pearson's correlation coefficient, our comparable detection methods can extract the repeatable features of the packet arrivals. The extensive simulations were tested for the accuracy of detection. We then performed experiments with several datasets and our results affirm that the proposed method can differentiate Traffic of an Attack source from legitimate Traffic with a quick response. We also discuss approaches to improve our proposed methods at the conclusion of this paper.

  • chaos theory based detection against network mimicking ddos Attacks
    IEEE Communications Letters, 2009
    Co-Authors: Ashley Chonka, Jaipal Singh, Wanlei Zhou
    Abstract:

    DDoS Attack Traffic is difficult to differentiate from legitimate network Traffic during transit from the Attacker, or zombies, to the victim. In this paper, we use the theory of network self-similarity to differentiate DDoS flooding Attack Traffic from legitimate self-similar Traffic in the network. We observed that DDoS Traffic causes a strange attractor to develop in the pattern of network Traffic. From this observation, we developed a neural network detector trained by our DDoS prediction algorithm. Our preliminary experiments and analysis indicate that our proposed chaotic model can accurately and effectively detect DDoS Attack Traffic. Our approach has the potential to not only detect Attack Traffic during transit, but to also filter it.

Yang Xiang - One of the best experts on this subject based on the ideXlab platform.

  • cloud security defence to protect cloud computing against http dos and xml dos Attacks
    Journal of Network and Computer Applications, 2011
    Co-Authors: Ashley Chonka, Wanlei Zhou, Yang Xiang, Alessio Bonti
    Abstract:

    Cloud computing is still in its infancy in regards to its software as services (SAS), web services, utility computing and platform as services (PAS). All of these have remained individualized systems that you still need to plug into, even though these systems are heading towards full integration. One of the most serious threats to cloud computing itself comes from HTTP Denial of Service or XML-Based Denial of Service Attacks. These types of Attacks are simple and easy to implement by the Attacker, but to security experts they are twice as difficult to stop. In this paper, we recreate some of the current Attacks that Attackers may initiate as HTTP and XML. We also offer a solution to traceback through our Cloud TraceBack (CTB) to find the source of these Attacks, and introduce the use of a back propagation neutral network, called Cloud Protector, which was trained to detect and filter such Attack Traffic. Our results show that we were able to detect and filter most of the Attack messages and were able to identify the source of the Attack within a short period of time.

  • low rate ddos Attacks detection and traceback by using new information metrics
    IEEE Transactions on Information Forensics and Security, 2011
    Co-Authors: Yang Xiang, Wanlei Zhou
    Abstract:

    A low-rate distributed denial of service (DDoS) Attack has significant ability of concealing its Traffic because it is very much like normal Traffic. It has the capacity to elude the current anomaly-based detection schemes. An information metric can quantify the differences of network Traffic with various probability distributions. In this paper, we innovatively propose using two new information metrics such as the generalized entropy metric and the information distance metric to detect low-rate DDoS Attacks by measuring the difference between legitimate Traffic and Attack Traffic. The proposed generalized entropy metric can detect Attacks several hops earlier (three hops earlier while the order α = 10 ) than the traditional Shannon metric. The proposed information distance metric outperforms (six hops earlier while the order α = 10) the popular Kullback-Leibler divergence approach as it can clearly enlarge the adjudication distance and then obtain the optimal detection sensitivity. The experimental results show that the proposed information metrics can effectively detect low-rate DDoS Attacks and clearly reduce the false positive rate. Furthermore, the proposed IP traceback algorithm can find all Attacks as well as Attackers from their own local area networks (LANs) and discard Attack Traffic.

David R Cheriton - One of the best experts on this subject based on the ideXlab platform.

  • active internet Traffic filtering real time response to denial of service Attacks
    USENIX Annual Technical Conference, 2005
    Co-Authors: Katerina Argyraki, David R Cheriton
    Abstract:

    This paper describes Active Internet Traffic Filtering (AITF), a mechanism for blocking highly distributed denial-of-service (DDoS) Attacks. These Attacks are an acute contemporary problem, with few practical solutions available today; we describe in this paper the reasons why no effective DDoS filtering mechanism has been deployed yet. We show that the current Internet's routers have sufficient filtering resources to thwart such Attacks, with the condition that Attack Traffic be blocked close to its sources; AITF leverages this observation. Our results demonstrate that AITF can block a million-flow Attack within seconds, while it requires only tens of thousands of wire-speed filters per participating router -- an amount easily accommodated by today's routers. AITF can be deployed incrementally and yields benefits even to the very first adopters.

  • active internet Traffic filtering real time response to denial of service Attacks
    arXiv: Networking and Internet Architecture, 2003
    Co-Authors: Katerina Argyraki, David R Cheriton
    Abstract:

    Denial of Service (DoS) Attacks are one of the most challenging threats to Internet security. An Attacker typically compromises a large number of vulnerable hosts and uses them to flood the victim's site with malicious Traffic, clogging its tail circuit and interfering with normal Traffic. At present, the network operator of a site under Attack has no other resolution but to respond manually by inserting filters in the appropriate edge routers to drop Attack Traffic. However, as DoS Attacks become increasingly sophisticated, manual filter propagation becomes unacceptably slow or even infeasible. In this paper, we present Active Internet Traffic Filtering, a new automatic filter propagation protocol. We argue that this system provides a guaranteed, significant level of protection against DoS Attacks in exchange for a reasonable, bounded amount of router resources. We also argue that the proposed system cannot be abused by a malicious node to interfere with normal Internet operation. Finally, we argue that it retains its efficiency in the face of continued Internet growth.

Weibo Gong - One of the best experts on this subject based on the ideXlab platform.

  • adaptive defense against various network Attacks
    IEEE Journal on Selected Areas in Communications, 2006
    Co-Authors: Cliff C Zou, Nick Duffield, Don Towsley, Weibo Gong
    Abstract:

    In defending against various network Attacks, such as distributed denial-of-service (DDoS) Attacks or worm Attacks, a defense system needs to deal with various network conditions and dynamically changing Attacks. Therefore, a good defense system needs to have a built-in "adaptive defense" functionality based on cost minimization-adaptively adjusting its configurations according to the network condition and Attack severity in order to minimize the combined cost introduced by false positives (misidentify normal Traffic as Attack) and false negatives (misidentify Attack Traffic as normal) at any time. In this way, the adaptive defense system can generate fewer false alarms in normal situations or under light Attacks with relaxed defense configurations, while protecting a network or a server more vigorously under severe Attacks. In this paper, we present concrete adaptive defense system designs for defending against two major network Attacks: SYN flood DDoS Attack and Internet worm infection. The adaptive defense is a high-level system design that can be built on various underlying nonadaptive detection and filtering algorithms, which makes it applicable for a wide range of security defenses

  • adaptive defense against various network Attacks
    Conference on Steps to Reducing Unwanted Traffic on Internet, 2005
    Co-Authors: Cliff C Zou, Nick Duffield, Don Towsley, Weibo Gong
    Abstract:

    In defending against various network Attacks, such as Distributed Denial-of-Service (DDoS) Attacks or worm Attacks, a defense system needs to deal with various network conditions and dynamically changing Attacks. In this paper, we introduce an "adaptive defense" principle based on cost minimization - a defense system adaptively adjusts its configurations according to the network condition and Attack severity in order to minimize the combined cost introduced by false positives (misidentify normal Traffic as Attack) and false negatives (misidentify Attack Traffic as normal) at any time. In this way, the adaptive defense system generates fewer false alarms in normal situations (or under light Attacks) with relaxed defense configurations, while protecting a network or a server more vigorously under severe Attacks. Specifically, we present detailed adaptive defense system designs for defending against two major network Attacks: SYN flood DDoS Attack and Internet worm infection. The adaptive defense is a high-level system design that can be built on top of various non-adaptive detection and filtering algorithms, which makes it applicable for a wide range of security defenses.

Mercy S Shalinie - One of the best experts on this subject based on the ideXlab platform.

  • probabilistic neural network based Attack Traffic classification
    International Conference on Advanced Computing, 2012
    Co-Authors: V Akilandeswari, Mercy S Shalinie
    Abstract:

    This paper surveys with the emerging research on various methods to identify the legitimate/illegitimate Traffic on the network. Here, the focus is on the effective early detection scheme for distinguishing Distributed Denial of Service (DDoS) Attack Traffic from normal flash crowd Traffic. The basic characteristics used to distinguish Distributed Denial of Service (DDoS) Attacks from flash crowds are access intents, client request rates, cluster overlap, distribution of source IP address, distribution of clients and speed of Traffic. Various techniques related to these metrics are clearly illustrated and corresponding limitations are listed out with their justification. A new method is proposed in this paper which builds a reliable identification model for flash crowd and DDoS Attacks. The proposed Probabilistic Neural Network based Traffic pattern classification method is used for effective classification of Attack Traffic from legitimate Traffic. The proposed technique uses the normal Traffic profile for their classification process which consists of single and joint distribution of various packet attributes. The normal profile contains uniqueness in Traffic distribution and also hard for the Attackers to mimic as legitimate flow. The proposed method achieves highest classification accuracy for DDoS flooding Attacks with less than 1% of false positive rate.