Detecting DDoS Attacks against Web Server Using Time Series Analysis

来源 :Wuhan University Journal of Natural Sciences | 被引量 : 0次 | 上传用户:jackyzero123
下载到本地 , 更方便阅读
声明 : 本文档内容版权归属内容提供方 , 如果您对本文有版权争议 , 可与客服联系进行内容授权或下架
论文部分内容阅读
Distributed Denial of Service (DDoS) attack is a major threat to the availability of Web service. The inherent presence of self-similarity in Web traffic motivates the applicability of time series analysis in the study of the burst feature of DDoS attack. This paper presents a method of detecting DDoS attacks against Web server by analyzing the abrupt change of time series data obtained from Web traffic. Time series data are specified in reference sliding window and test sliding window, and the abrupt change is modeled using Auto-Regressive (AR) process. By comparing two adjacent non-overlapping windows of the time series, the attack traffic could be detected at a time point. Combined with alarm correlation and location correlation, not only the presence of DDoS attack, but also its occurring time and location can be determined. The experimental results in a test environment are illustrated to justify our method. Distributed Denial of Service (DDoS) attack is a major threat to the availability of Web service. The inherent presence of self-similarity in Web traffic motivates the applicability of time series analysis in the study of the burst feature of DDoS attack. This paper presents a method of detecting DDoS attacks against Web server by analyzing the abrupt change of time series data obtained from Web traffic. Time series data are specified in reference sliding window and test sliding window, and the abrupt change is modeled using Auto-Regressive (AR) process. By comparing two adjacent non-overlapping windows of the time series, the attack traffic could be detected at a time point. Combined with alarm correlation and location correlation, not only the presence of DDoS attack, but also its occurring time and location can be determined. The experimental results in a test environment are illustrated to justify our method.
其他文献
10月27日,江西省全国青少年井冈山革命传统教育基地里热闹非凡,一群红领巾正在举办红军趣味运动会——运南瓜比赛!比赛后,一名队员即兴赋诗一首。井冈游江西省上饶市第十一小
目的 :总结支气管内膜结核HRCT表现以提高其影像诊断水平。材料与方法 :回顾性分析 10 3例支气管内膜结核患者HRCT影像资料和临床资料。结果 :支气管内膜结核的HRCT主要表现
公元291—311年,八大宗王互相火并,相继擅权,前后约占西晋一朝五分之二的时间,集中体现了那个朝代政治体制的主要特色。本文从见载僚佐的人数、籍贯、门望、辟除等客观指标入
《宋史·司马光传》以近七千个字记录了司马光一生的概况,涉及仁宗﹑英宗﹑神宗﹑哲宗四个朝代的事情,凸显了司马光的性格特征。本文欲从司马光谏仁宗立嗣一事,同时以《东都事略·
庐丰中心小学,是一所农村寄宿制完小。学校周边的自然村落聚居的均是畲族村民。千百年来的传承与积淀,畲族人民养成了勤劳、勇敢、节俭、朴实的品格,保留着憨厚、热情、纯朴
很多大型的门户网站,如搜狐、网易等,它们的访问流量通常相当大,某一时间段内可能有成千上万的用户同时浏览某个页面,为了使这些门户网站正常运营,它们大多使用多台服务器同
在古代,编纂正史乃国家大事。①在中韩两国悠久的文化交流过程中,史籍交流地位独特。在高丽朝之前的三国时代,两国的史籍交流已经开始,大量的中国史籍传人高句丽、百济和新罗
近年来 ,集中度及圆形分布已广泛用于分析传染病的季节特征。本文试用圆形分布及集中度法对莆田县 1991—2 0 0 0年麻疹的季节分布进行分析 ,报告如下。1 资料与方法1.1. 
唐恭陵,位于河南省洛阳市偃师缑氏镇滹沱村南的景山之巅。陵墓的主人李弘,系唐高宗李治的第五子、一代女皇武则天的长子。他两岁时,即被封为代王。显庆元年(656)又被立为太子
冯双双看着眼前昏迷了三天三夜的男朋友,眼泪都快流干了。可是他没办法,医生说,再过几个小时他要还不醒,估计真的就成植物人了。冯双双无法接受这个事实,她擦了擦眼泪,她要想