Online DDoS attack detection using Mahalanobis distance and Kernel-based learning algorithm. (15th October 2020)
- Record Type:
- Journal Article
- Title:
- Online DDoS attack detection using Mahalanobis distance and Kernel-based learning algorithm. (15th October 2020)
- Main Title:
- Online DDoS attack detection using Mahalanobis distance and Kernel-based learning algorithm
- Authors:
- Daneshgadeh Çakmakçı, Salva
Kemmerich, Thomas
Ahmed, Tarem
Baykal, Nazife - Abstract:
- Abstract: Distributed denial-of-service (DDoS) attacks are constantly evolving as the computer and networking technologies and attackers' motivations are changing. In recent years, several supervised DDoS detection algorithms have been proposed. However, these algorithms require a priori knowledge of the classes and cannot automatically adapt to frequently changing network traffic trends. This emphasizes the need for the development of new DDoS detection mechanisms that target zero-day and sophisticated DDoS attacks. In this paper, we propose an online, sequential, DDoS detection scheme that is suitable for use with multivariate data. The proposed algorithm utilizes a kernel-based learning algorithm, the Mahalanobis distance, and a chi-square test. Initially, we extract four entropy-based and four statistical features from network flows per minute as detection metrics. Then, we employ the kernel-based learning algorithm using the entropy features to detect input vectors that were suspected to be DDoS. This algorithm assumes no model for network traffic or DDoS. It constructs and adapts a dictionary of features that approximately span the subspace of normal behavior. Every T minutes, the Mahalanobis distance between suspicious vectors and the distribution of dictionary members is measured. Subsequently, the chi-square test is used to evaluate the Mahalanobis distance. The proposed DDoS detection scheme was applied to the CICIDS2017 dataset, and we compared the results withAbstract: Distributed denial-of-service (DDoS) attacks are constantly evolving as the computer and networking technologies and attackers' motivations are changing. In recent years, several supervised DDoS detection algorithms have been proposed. However, these algorithms require a priori knowledge of the classes and cannot automatically adapt to frequently changing network traffic trends. This emphasizes the need for the development of new DDoS detection mechanisms that target zero-day and sophisticated DDoS attacks. In this paper, we propose an online, sequential, DDoS detection scheme that is suitable for use with multivariate data. The proposed algorithm utilizes a kernel-based learning algorithm, the Mahalanobis distance, and a chi-square test. Initially, we extract four entropy-based and four statistical features from network flows per minute as detection metrics. Then, we employ the kernel-based learning algorithm using the entropy features to detect input vectors that were suspected to be DDoS. This algorithm assumes no model for network traffic or DDoS. It constructs and adapts a dictionary of features that approximately span the subspace of normal behavior. Every T minutes, the Mahalanobis distance between suspicious vectors and the distribution of dictionary members is measured. Subsequently, the chi-square test is used to evaluate the Mahalanobis distance. The proposed DDoS detection scheme was applied to the CICIDS2017 dataset, and we compared the results with those given by existing algorithms. It was demonstrated that the proposed online detection scheme outperforms almost all available DDoS classification algorithms with an offline learning process. Graphical abstract: Image 1 Highlights: Developing a novel DDoS detection algorithm named Enhanced Kernel Online AnomalyDetection (E-KOAD) algorithm. Using an up-to-date dictionary of normal traffic to measure the Mahalanobis distance in the algorithm. Proving that the detection accuracy of the algorithm with optimal thresholds is not sensitive to orange alarm resolving time. Proposing a feature vector based on a combination of statistical and entropy features in the literature. Employing a recent and reliable benchmark dataset from the Canadian Institute for Cybersecurityto validate the algorithm.. … (more)
- Is Part Of:
- Journal of network and computer applications. Volume 168(2020)
- Journal:
- Journal of network and computer applications
- Issue:
- Volume 168(2020)
- Issue Display:
- Volume 168, Issue 2020 (2020)
- Year:
- 2020
- Volume:
- 168
- Issue:
- 2020
- Issue Sort Value:
- 2020-0168-2020-0000
- Page Start:
- Page End:
- Publication Date:
- 2020-10-15
- Subjects:
- Online learning algorithm -- DDoS -- KOAD -- E-KOAD -- Mahalanobis distance -- Chi-square test
Microcomputers -- Periodicals
Computer networks -- Periodicals
Application software -- Periodicals
Micro-ordinateurs -- Périodiques
Réseaux d'ordinateurs -- Périodiques
Logiciels d'application -- Périodiques
Application software
Computer networks
Microcomputers
Periodicals
004.05
004 - Journal URLs:
- http://www.sciencedirect.com/science/journal/10848045 ↗
http://www.elsevier.com/journals ↗ - DOI:
- 10.1016/j.jnca.2020.102756 ↗
- Languages:
- English
- ISSNs:
- 1084-8045
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 5021.410600
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 14269.xml