Journal on Communications ›› 2018, Vol. 39 ›› Issue (7): 139-147.doi: 10.11959/j.issn.1000-436x.2018126

• Papers • Previous Articles     Next Articles

Detection method of LDoS attack based on ACK serial number step-length

Zhijun WU,Qingbo PAN,Meng YUE   

  1. School of Electronic Information &Automation,Civil Aviation University of China,Tianjin 300300,China
  • Revised:2018-05-08 Online:2018-07-01 Published:2018-08-08
  • Supported by:
    The Joint Foundation of National Natural Science Foundation and Civil Aviation Administration of China(U153310);The Major Program of Natural Science Foundation of Tianjin(17JCZDJC30900)

Abstract:

Low-rate denial of service (LDoS) attack is a potential security threat to big data centers and cloud computing platforms because of its strong concealment.Based on the analysis of network traffic during the LDoS attack,statistical analysis was given of ACK packets returned by the data receiver to the sender,and result reveals the sequence number step had the characteristics of volatility during the LDoS attack.The permutation entropy method was adopted to extract the characteristics of volatility.Hence,an LDoS attack detection method based on ACK serial number step permutation entropy was proposed.The serial number was sampled and the step length was calculated through collecting the ACK packets that received at the end of sender.Then,the permutation entropy algorithm with strong time-sensitive was used to detect the mutation step time,and achieve the goal of detecting LDoS attack.A test-bed was designed and built in the actual network environment for the purpose of verifying the proposed approach performance.Experimental results show that the proposed approach has better detection performance and has achieved better detection effect.

Key words: low-rate denial of service, ACK serial number step-length, permutation entropy, detection

CLC Number: 

No Suggested Reading articles found!