Безопасность информационных технологий (Mar 2011)
Distributed Denial of Service Detection with IPFIX Protocol
Abstract
In this article the existing methods of detecting Distributed Denial of Service attacks based on the analysis of network traffic or Netflow data is examined. Advantages and disadvantages of anomaly detection methods are listed. Authors suggest to use a method of maximum entropy estimation for the analysis of IPFIX data and propose an approach for detecting Distributed Denial of Service attacks.