Low-Rate DoS Attack Flows Filtering Based on Frequency Spectral Analysis

来源 :中国通信 | 被引量 : 0次 | 上传用户:usernameing
下载到本地 , 更方便阅读
声明 : 本文档内容版权归属内容提供方 , 如果您对本文有版权争议 , 可与客服联系进行内容授权或下架
论文部分内容阅读
In frequency domain,the power spectrum of Low-rate denial of service(LDoS) attacks is totally spread into the spectrum of normal traffic.It is a challenging task to detect and filter LDoS attack flows from the normal traffic.Based on the analysis of LDoS attack flows and legitimate TCP traffic in time and frequency domains,the periodicity of the TCP traffic and LDoS attack flows is explored to facilitate the research of network traffic processing.Hence,an approach of LDoS attack flow filtering based on frequency spectrum analysis is proposed.In this approach,the TCP traffic and LDoS attack flows are transformed from the time domain into the frequency domain.Then the round-trip time(RTT) is estimated by using frequency domain search method.Analysis of amplitude spectrum shows that TCP traffic energy is mainly concentrated on the points of n/RTT.Therefore,a comb filter using infinite impulse response(IIR) filter is designed to filter out the LDoS attack flows in frequency domain,while most legitimate TCP traffic energy at the points of n/RTT are pass through.Experimental results show that the maximum pass rate for legitimate TCP traffic reaches 92.55%,while the maximum filtration rate of LDoS attack flows reaches 81.36%.The proposed approach can effectively filter the LDoS attack flows while less impact on the legitimate TCP traffic. In frequency domain, the power spectrum of Low-rate denial of service (LDoS) attacks is totally spread into the spectrum of normal traffic. It is a challenging task to detect and filter LDoS attacks flows from the normal traffic. LDoS attack flows and legitimate TCP traffic in time and frequency domains, the periodicity of the TCP traffic and LDoS attack flows is explored to facilitate the research of network traffic processing .ence, an approach of LDoS attack flow filtering based on frequency spectrum analysis is proposed . This approach, the TCP traffic and LDoS attack flows are transformed from the time domain into the frequency domain. The round-trip time (RTT) is estimated by using frequency domain search method. Analysis of amplitude spectrum shows that TCP traffic energy is mainly concentrated on the points of n / RTT.Therefore, a comb filter using infinite impulse response (IIR) filter is designed to filter out the LDoS attack flows in frequency domain, while mo st may TCP traffic energy at the points of n / RTT are pass through. Experimental results show that the maximum pass rate for legitimate TCP traffic reaches 92.55%, while the maximum filtration rate of LDoS attack flows reaches 81.36%. filter the LDoS attack flows while less impact on the legitimate TCP traffic.
其他文献
学生是学习和发展的主体,要尊重学生在学习过程中的独特感受、体验和理解。小学数学课堂的“层次性体验”就是根据学习材料的特点和学生的认知规律,组织学生在初步感知、操作
目的了解沧州市新华区2011-2013年餐饮具监测结果,分析影响餐饮具消毒效果的主要因素,加强餐饮具消毒效果的监测,提高餐饮单位的管理水平,强化工作人员的消毒意识,最大程度地
期刊
总体来说,远程电视直播可通过有线和无线两种方式进行信号传输。其中,光纤为有线传输方式,而卫星、微波、3G均为无线方式。无线传输方式较早使用的是微波,当前广泛应用、最为流行的卫星上行车(DSNG),通过3G技术进行传输尚处于起步阶段。    4种传输方式对比    一、光纤  对于远程电视直播而言,有线传输方式主要是指通过前期施工,将现场直播的视音频信号通过光纤(电信运营商或广电的干线网络)实时传送
期刊
期刊
阅读是学习英语的一种重要的方式。最近几年,尽管这一重要的能力被教师和学生忽略,更加注重听和说能力的培养。为了提高大学生英语阅读能力,我们有必要讨论与阅读相关的一些
Catalytic pyrolysis process (CPP) producing ethylene and propylene from parafifn base atmospheric residue was developed by RIPP and its ifrst in the world unit
期刊