Characterizing flash events and distributed denial‐of‐service attacks: an empirical investigation. Issue 13 (6th March 2016)
- Record Type:
- Journal Article
- Title:
- Characterizing flash events and distributed denial‐of‐service attacks: an empirical investigation. Issue 13 (6th March 2016)
- Main Title:
- Characterizing flash events and distributed denial‐of‐service attacks: an empirical investigation
- Authors:
- Bhandari, Abhinav
Sangal, Amrit Lal
Kumar, Krishan - Abstract:
- Abstract: In the information age where Internet is the most important means of delivery of plethora of services, distributed denial‐of‐service (DDoS) attacks have emerged as one of the most serious threat. Strategic, security, social, and financial implications of these attacks have ceaselessly alarmed the entire cyber community. To obviate a DDoS attack and mitigate its impact, there is an irrevocable prerequisite to accurately detect them promptly. An inherent challenge in addressing this issue is to efficiently distinguish these attacks from characteristically analogous flash events (FEs) which are bona fide occurrences generated by legitimate users. Most of the studies have focused on finding out the unique characteristics of DDoS attacks in isolation, with the peril of false alarms heuristically. To preclude this, it is pertinent to fundamentally focus on identifying the unique characteristics of FE vis‐a‐vis DDoS attacks ab initio which has been the basis of this work. The aim of this paper is to formulate the taxonomy of FEs and compare the characteristics of FEs and DDoS attacks to segregate these using several empirical metrics. Real and emulation datasets have been used to validate the characteristics of both. The extensive analysis in this study establishes that there are numerous technical dissimilarities that can be exploited to separate these similar looking events. Copyright © 2016 John Wiley & Sons, Ltd. Abstract : Strategic, security, social, and financialAbstract: In the information age where Internet is the most important means of delivery of plethora of services, distributed denial‐of‐service (DDoS) attacks have emerged as one of the most serious threat. Strategic, security, social, and financial implications of these attacks have ceaselessly alarmed the entire cyber community. To obviate a DDoS attack and mitigate its impact, there is an irrevocable prerequisite to accurately detect them promptly. An inherent challenge in addressing this issue is to efficiently distinguish these attacks from characteristically analogous flash events (FEs) which are bona fide occurrences generated by legitimate users. Most of the studies have focused on finding out the unique characteristics of DDoS attacks in isolation, with the peril of false alarms heuristically. To preclude this, it is pertinent to fundamentally focus on identifying the unique characteristics of FE vis‐a‐vis DDoS attacks ab initio which has been the basis of this work. The aim of this paper is to formulate the taxonomy of FEs and compare the characteristics of FEs and DDoS attacks to segregate these using several empirical metrics. Real and emulation datasets have been used to validate the characteristics of both. The extensive analysis in this study establishes that there are numerous technical dissimilarities that can be exploited to separate these similar looking events. Copyright © 2016 John Wiley & Sons, Ltd. Abstract : Strategic, security, social, and financial implications of distributed denial‐of‐service (DDoS) attacks have ceaselessly alarmed the entire cyber community. This paper empirically investigates the characteristics offlash events and DDoS attacks with an aim to accurately characterize the attack traffic and thus mitigate the impact of these attacks with minimum collateral damage. The real and emulated datasets have been used to the required purposes. Taxonomy of FEs has also been presented in this paper. … (more)
- Is Part Of:
- Security and communication networks. Volume 9:Issue 13(2016)
- Journal:
- Security and communication networks
- Issue:
- Volume 9:Issue 13(2016)
- Issue Display:
- Volume 9, Issue 13 (2016)
- Year:
- 2016
- Volume:
- 9
- Issue:
- 13
- Issue Sort Value:
- 2016-0009-0013-0000
- Page Start:
- 2222
- Page End:
- 2239
- Publication Date:
- 2016-03-06
- Subjects:
- DDoS attacks -- flash event -- page access behavior -- flow similarity -- botnet
Computer networks -- Security measures -- Periodicals
Computer security -- Periodicals
Cryptography -- Periodicals
005.805 - Journal URLs:
- http://onlinelibrary.wiley.com/journal/10.1002/(ISSN)1939-0122 ↗
https://www.hindawi.com/journals/scn/ ↗
http://onlinelibrary.wiley.com/ ↗ - DOI:
- 10.1002/sec.1472 ↗
- Languages:
- English
- ISSNs:
- 1939-0114
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library HMNTS - ELD Digital store
- Ingest File:
- 1286.xml