FRRED: Fourier robust RED algorithm to detect and mitigate LDoS attacks

Zhaomin Chen, Thi Ngoc Diep Pham, Chai Kiat Yeo, Bu Sung Lee, Chiew Tong Lau
{"title":"FRRED: Fourier robust RED algorithm to detect and mitigate LDoS attacks","authors":"Zhaomin Chen, Thi Ngoc Diep Pham, Chai Kiat Yeo, Bu Sung Lee, Chiew Tong Lau","doi":"10.1109/ZINC.2017.7968651","DOIUrl":null,"url":null,"abstract":"As most of consumer electronics are connected to the Internet, network attacks can cause massive damage and loss of data to the users. By sending periodic packet bursts to bottleneck routers, Low-Rate Denial-of-Service (LDoS) attacks can degrade the throughput of TCP applications while being hard to be detected. In this paper, we introduce Power Spectrum Density Entropy (PSD-entropy) to detect LDoS attacks. We also propose a Fourier transform based Robust RED (FRRED) queuing algorithm to preserve TCP throughput when faced with LDoS attacks. This novel Active Queue Management (AQM) Algorithm firstly detects the suspicious attack packets based on their arrival time and then filter the attack packets based on Power Spectrum Density (PSD) entropy. We perform extensive simulations in NS-3 to evaluate the performance of FRRED. Compared to other AQM algorithms, FRRED has the lowest False Positive Rate and can preserve nearly the full TCP throughput.","PeriodicalId":307604,"journal":{"name":"2017 Zooming Innovation in Consumer Electronics International Conference (ZINC)","volume":"3 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2017-05-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"14","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2017 Zooming Innovation in Consumer Electronics International Conference (ZINC)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ZINC.2017.7968651","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 14

Abstract

As most of consumer electronics are connected to the Internet, network attacks can cause massive damage and loss of data to the users. By sending periodic packet bursts to bottleneck routers, Low-Rate Denial-of-Service (LDoS) attacks can degrade the throughput of TCP applications while being hard to be detected. In this paper, we introduce Power Spectrum Density Entropy (PSD-entropy) to detect LDoS attacks. We also propose a Fourier transform based Robust RED (FRRED) queuing algorithm to preserve TCP throughput when faced with LDoS attacks. This novel Active Queue Management (AQM) Algorithm firstly detects the suspicious attack packets based on their arrival time and then filter the attack packets based on Power Spectrum Density (PSD) entropy. We perform extensive simulations in NS-3 to evaluate the performance of FRRED. Compared to other AQM algorithms, FRRED has the lowest False Positive Rate and can preserve nearly the full TCP throughput.
FRRED:检测和减轻LDoS攻击的傅立叶鲁棒RED算法
由于大多数消费电子产品都连接到互联网,网络攻击会给用户造成巨大的损害和数据丢失。低速率拒绝服务攻击(Low-Rate Denial-of-Service, LDoS)通过周期性地向瓶颈路由器发送数据包爆发,降低TCP应用程序的吞吐量,并且难以被检测到。本文引入功率谱密度熵(PSD-entropy)来检测LDoS攻击。我们还提出了一种基于傅里叶变换的鲁棒RED (FRRED)队列算法,以在面对ddos攻击时保持TCP吞吐量。该算法首先根据可疑攻击报文的到达时间对可疑攻击报文进行检测,然后根据功率谱密度熵对可疑攻击报文进行过滤。我们在NS-3中进行了大量的模拟来评估FRRED的性能。与其他AQM算法相比,FRRED具有最低的误报率,并且可以保持几乎全部的TCP吞吐量。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信