vix.ing · top · new · best · stats · spec

DDoS Attacks with Randomized Traffic Innovation: Botnet Identification\n Challenges and Strategies

2016/06/13 by Vincenzo Matta, Matta, Vincenzo, Mario Di Mauro +3
Computer Science · #Anomaly Detection Techniques and Applications #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #Information Theory (cs.IT) #Internet Traffic Analysis and Secure E-voting #Network Security and Intrusion Detection #Networking and Internet Architecture (cs.NI)

paper · pdf · doi:10.48550/arxiv.1606.03986

openalex publication_date 2016/06/13 · openalex created_date 2022/10/01 · openalex updated_date 2026/07/28

Abstract

Distributed Denial-of-Service (DDoS) attacks are usually launched through the\nbotnet, an "army" of compromised nodes hidden in the network. Inferential\ntools for DDoS mitigation should accordingly enable an early and reliable\ndiscrimination of the normal users from the compromised ones. Unfortunately,\nthe recent emergence of attacks performed at the application layer has\nmultiplied the number of possibilities that a botnet can exploit to conceal its\nmalicious activities. New challenges arise, which cannot be addressed by simply\nborrowing the tools that have been successfully applied so far to earlier DDoS\nparadigms. In this work, we offer basically three contributions: i) we\nintroduce an abstract model for the aforementioned class of attacks, where the\nbotnet emulates normal traffic by continually learning admissible patterns from\nthe environment; ii) we devise an inference algorithm that is shown to\nprovide a consistent (i.e., converging to the true solution as time progresses)\nestimate of the botnet possibly hidden in the network; and iii) we verify the\nvalidity of the proposed inferential strategy over real network traces.\n

Related