Skip to main navigation Skip to search Skip to main content

Lightweight detection of DoS attacks

  • Mahidol University
  • National Electronics and Computer Technology Center

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

13 Citations (Scopus)

Abstract

Denial of Service (DoS) attacks have continued to evolve and impact availability of the Internet infrastructure. Many researchers in the field of network security and system survivability have been developing mechanisms to detect DoS attacks. By doing so they hope to maximize accurate detections (true-positive) and minimize non-justified detections (false-positive). This research proposes a lightweight method to identify DoS attacks by analyzing host behaviors. Our method is based on the concept of BLINd Classification or BLINC: no access to packet payload, no knowledge of port numbers, and no additional information other than what current flow collectors provide. Rather than using pre-defined signatures or rules as in typical Intrusion Detection Systems, BLINC maps flows into graphlets of each attack pattern. In this work we create three types of graphlets for the following DoS attack patterns: SYN flood, ICMP flood, and host scan. Results show that our method can identify all occurrences and all hosts associated with attack activities, with a low percentage of false positive.

Original languageEnglish
Title of host publicationICON 2007 - Proceedings of the 2007 15th IEEE International Conference on Networks
Pages77-82
Number of pages6
DOIs
Publication statusPublished - 2007
Event15th IEEE International Conference on Networks, ICON 2007 - Adelaide, SA, Australia
Duration: 19 Nov 200721 Nov 2007

Publication series

NameICON 2007 - Proceedings of the 2007 15th IEEE International Conference on Networks

Conference

Conference15th IEEE International Conference on Networks, ICON 2007
Country/TerritoryAustralia
CityAdelaide, SA
Period19/11/0721/11/07

UN SDGs

This output contributes to the following UN Sustainable Development Goals (SDGs)

  1. SDG 9 - Industry, Innovation, and Infrastructure
    SDG 9 Industry, Innovation, and Infrastructure

Fingerprint

Dive into the research topics of 'Lightweight detection of DoS attacks'. Together they form a unique fingerprint.

Cite this