{"title":"DOFUR: DDoS Forensics Using MapReduce","authors":"Rana Khattak, S. Bano, Shujaat Hussain, Z. Anwar","doi":"10.1109/FIT.2011.29","DOIUrl":null,"url":null,"abstract":"Currently we have seen a very sharp increase in network traffic. Due to this increase, the size of attack log files has also increased greatly and using conventional techniques to mine the logs and get some meaningful analyses about the DDoS attacker's location and possible victims has become increasingly difficult. We propose a technique using Hadoop's MapReduce to deduce results efficiently and quickly which would otherwise take a long time if conventional means were used. The aim of this paper is to describe how we designed a framework to detect those packets in a dataset which belong to a DDoS attack using MapReduce provided by Hadoop. Experimental results using a real dataset show that parallelising DDoS detection can greatly improve efficiency.","PeriodicalId":101923,"journal":{"name":"2011 Frontiers of Information Technology","volume":"1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2011-12-19","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"14","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2011 Frontiers of Information Technology","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/FIT.2011.29","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 14
Abstract
Currently we have seen a very sharp increase in network traffic. Due to this increase, the size of attack log files has also increased greatly and using conventional techniques to mine the logs and get some meaningful analyses about the DDoS attacker's location and possible victims has become increasingly difficult. We propose a technique using Hadoop's MapReduce to deduce results efficiently and quickly which would otherwise take a long time if conventional means were used. The aim of this paper is to describe how we designed a framework to detect those packets in a dataset which belong to a DDoS attack using MapReduce provided by Hadoop. Experimental results using a real dataset show that parallelising DDoS detection can greatly improve efficiency.