Go home now Header Background Image
Search
Submission Procedure
share: |
 
Follow us
 
 
 
 
Volume 15 / Issue 2

available in:   PDF (623 kB) PS (1 MB)
 
get:  
Similar Docs BibTeX   Write a comment
  
get:  
Links into Future
 
DOI:   10.3217/jucs-015-02-0488

 

A New Detection Method for Distributed Denial-of-Service Attack Traffic based on Statistical Test

Chin-Ling Chen (National Pingtung Institute of Commerce, Taiwan)

Abstract: This study has proposed a new detection method for DDoS attack traffic based on two-sample t-test. We first investigate the statistics of normal SYN arrival rate (SAR) and confirm it follows normal distribution. The proposed method identifies the attack by testing 1) the difference between incoming SAR and normal SAR, and 2) the difference between the number of SYN and ACK packets. The experiment results show that the possibilities of both false positives and false negatives are very low. The proposed mechanism is also demonstrated to have the capability of detecting DDoS attack quickly.

Keywords: network monitoring, security and protection, statistical computing

Categories: C.2.0, C.2.3, G.3