Combating DDoS attacks at their sources is still in its infancy. In tttis paper, a noaparametric adaptive CUSUM (cumulative sum) method is presented, which is proven efficient in detecting SYN flooding attacks close...Combating DDoS attacks at their sources is still in its infancy. In tttis paper, a noaparametric adaptive CUSUM (cumulative sum) method is presented, which is proven efficient in detecting SYN flooding attacks close to their sources. Different from other CUSUM methods, this new method has two distinct features: (1) its detection threshold can adapt itself to various traffic conditions and (2) it can timely detect the end of an attack within a required delay. Trace-driven simulations are conducted to validate the efficacy of this method in detecting SYN flooding attacks, and the results show that the nonparametric adaptive CUSUM method excels in detecting low-rate attacks.展开更多
基金Supported by the Special Fund of Central College Basic Scientific Research Bursary (DUT1ORC(3)225)Key Discipline Construction Fund of Liaoning Province
文摘Combating DDoS attacks at their sources is still in its infancy. In tttis paper, a noaparametric adaptive CUSUM (cumulative sum) method is presented, which is proven efficient in detecting SYN flooding attacks close to their sources. Different from other CUSUM methods, this new method has two distinct features: (1) its detection threshold can adapt itself to various traffic conditions and (2) it can timely detect the end of an attack within a required delay. Trace-driven simulations are conducted to validate the efficacy of this method in detecting SYN flooding attacks, and the results show that the nonparametric adaptive CUSUM method excels in detecting low-rate attacks.