{"title":"Classification of DDoS Attacks and Flash Events using Source IP Entropy and Traffic Cluster Entropy","authors":"Srinath Sureshkumar","doi":"10.1109/ICECCT52121.2021.9616887","DOIUrl":null,"url":null,"abstract":"Distributed Denial of Services (DDoS) attack is one of the most dangerous exploits capable of affecting an organization’s reputation and functioning. Today several tools are available to launch one with ease. It is extremely difficult to differentiate these attacks from flash events. Flash Crowds are events where plenty of legitimate requests for a common web resource come into the server. When the incoming traffic into a server exceeds the peak limit the possibility of a server crashing or hanging also increases. Due to the congestion caused by the huge amount of illegitimate traffic in DDoS attacks, the server is unable to complete the legitimate service requests and the server’s resources are overloaded with these illegitimate requests. We propose an Entropy based classification technique which differentiates legitimate flash crowds and illegitimate DDoS attack traffic.","PeriodicalId":155129,"journal":{"name":"2021 Fourth International Conference on Electrical, Computer and Communication Technologies (ICECCT)","volume":"9 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-09-15","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2021 Fourth International Conference on Electrical, Computer and Communication Technologies (ICECCT)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICECCT52121.2021.9616887","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
Abstract
Distributed Denial of Services (DDoS) attack is one of the most dangerous exploits capable of affecting an organization’s reputation and functioning. Today several tools are available to launch one with ease. It is extremely difficult to differentiate these attacks from flash events. Flash Crowds are events where plenty of legitimate requests for a common web resource come into the server. When the incoming traffic into a server exceeds the peak limit the possibility of a server crashing or hanging also increases. Due to the congestion caused by the huge amount of illegitimate traffic in DDoS attacks, the server is unable to complete the legitimate service requests and the server’s resources are overloaded with these illegitimate requests. We propose an Entropy based classification technique which differentiates legitimate flash crowds and illegitimate DDoS attack traffic.