IET Information Security (Mar 2022)

LDoS attack detection method based on traffic classification prediction

  • Liang Liu,
  • Yue Yin,
  • Zhijun Wu,
  • Qingbo Pan,
  • Meng Yue

DOI
https://doi.org/10.1049/ise2.12046
Journal volume & issue
Vol. 16, no. 2
pp. 86 – 96

Abstract

Read online

Abstract Aiming at the low rate and strong concealment of low‐rate Denial of Service (LDoS) attacks, the calculation of traffic Hurst index is combined with traffic classification, and a machine learning LDoS attack detection method based on search sorting is proposed. The method first calculates the segmentation Hurst exponent of each flow, and constructs a traffic similarity matrix as a statistical feature. Then, using the improved model XGBoost of the Gradient Boosting Decision Tree (GBDT), the traffic is classified and predicted. The network angle distinguishes between normal traffic and abnormal Origin‐Destination (OD) flows containing LDoS attacks, thereby achieving the purpose of detecting LDoS attacks. The method in this study was validated using the US public network dataset Abilene. The experimental results show that the global LDoS attack traffic detection method based on the Hurst index and GBDT algorithm achieves better detection results under different attack rates.

Keywords