Traffic-flow analysis for source-side DDoS recognition on 5G environments. (15th June 2019)
- Record Type:
- Journal Article
- Title:
- Traffic-flow analysis for source-side DDoS recognition on 5G environments. (15th June 2019)
- Main Title:
- Traffic-flow analysis for source-side DDoS recognition on 5G environments
- Authors:
- Sotelo Monge, Marco Antonio
Herranz González, Andrés
Lorenzo Fernández, Borja
Maestre Vidal, Diego
Rius García, Guillermo
Maestre Vidal, Jorge - Abstract:
- Abstract: This paper introduces a novel approach for detecting the participation of a protected network device in flooding-based Distributed Denial of Service attacks. With this purpose, the traffic flows are inspected at source-side looking for discordant behaviors. In contrast to most previous solutions, the proposal assumes the non-stationarity and heterogeneity inherent in the emergent communication environment. In particular, the approach takes advantage of the monitorization and knowledge acquisition capabilities implemented in the SELFNET (H2020-ICT-2014-2/671672) project, which facilitates its implementation as a self-organizing solution on 5G mobile networks. Monitorization, feature extraction and knowledge acquisition tasks are carried out on centralized control plane, hence the proposed architecture minimizes the impact on operational performance and prompts the end-points mobility. The preliminary results observed when considering different metrics, adjustment parameters, and a dataset with traffic observed in 61 real devices proven efficiency when distinguishing normal activities from DDoS behaviors of different intensity. With an optimal granularity selection, the highest AUC reached values close to 1.0 when measured under the most intense attacks, hence demonstrating optimal TPR and FPR relationships by adapting to the instantiated use cases.
- Is Part Of:
- Journal of network and computer applications. Volume 136(2019)
- Journal:
- Journal of network and computer applications
- Issue:
- Volume 136(2019)
- Issue Display:
- Volume 136, Issue 2019 (2019)
- Year:
- 2019
- Volume:
- 136
- Issue:
- 2019
- Issue Sort Value:
- 2019-0136-2019-0000
- Page Start:
- 114
- Page End:
- 131
- Publication Date:
- 2019-06-15
- Subjects:
- 5G -- Denial of service -- Intrusion detection systems -- Source-side detection -- Knowledge acquisition
Microcomputers -- Periodicals
Computer networks -- Periodicals
Application software -- Periodicals
Micro-ordinateurs -- Périodiques
Réseaux d'ordinateurs -- Périodiques
Logiciels d'application -- Périodiques
Application software
Computer networks
Microcomputers
Periodicals
004.05
004 - Journal URLs:
- http://www.sciencedirect.com/science/journal/10848045 ↗
http://www.elsevier.com/journals ↗ - DOI:
- 10.1016/j.jnca.2019.02.030 ↗
- Languages:
- English
- ISSNs:
- 1084-8045
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 5021.410600
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 10158.xml