A DoS Detection Method Based on Composition Self-Similarity

作者:Jian-Qi, Zhu; Feng, Fu; Kim, Chong-kwon*; Ke-xin, Yin; Yan-Heng, Liu
来源:KSII Transactions on Internet and Information Systems, 2012, 6(5): 1463-1478.
DOI:10.3837/tiis.2012.05.012

摘要

Based on the theory of local-world network, the composition self-similarity (CSS) of network traffic is presented for the first time in this paper for the study of DoS detection. We propose the concept of composition distribution graph and design the relative operations. The (R/S)(d) algorithm is designed for calculating the Hurst parameter. Based on composition distribution graph and Kullback Leibler (KL) divergence, we propose the composition self-similarity anomaly detection (CSSD) method for the detection of DoS attacks. We evaluate the effectiveness of the proposed method. Compared to other entropy based anomaly detection methods, our method is more accurate and with higher sensitivity in the detection of DoS attacks.