International Peer-Reviewed Journal•Open Access•ISSN 2456-8880
irejournals@gmail.com•+91-7433024337

Home / Current Issue / Paper 1700357

1700357 Vol 1 · Issue 9 Download Paper

DoS Attack Detection System Using Multivariate Correlation Analysis

CHAMAKURI MADHURIMA Chintakrindi Geaya Sri Bitra Srilatha Jonnadula Raja Sri Ch.Vijayananda Ratnam

Subject area: Science,Engineering and Technology  ·  Area of research: Computer science and Engineering

Abstract

There are many interconnected systems which we are working in our daily life i.e., cloud computing servers, web servers. These systems are now under the threat of various network attacks. Out of those, Denial of Service (DoS) causes serious impact to these interconnected systems. It happened so, because the server remains busy with the fake requests sent from the attackers by serving those fake requests. So, to increase the efficiency it is important to detect and prevent DoS attacks. In this paper, we present a DoS attack detection system that uses Multivariate Correlation Analysis (MCA) for accurate network traffic characterization by extracting the geometrical correlations between network traffic features. Our MCA based DoS attack detection system uses anomaly-based detection technique to recognize the attack. This makes our solution capable of detecting known and unknown DoS attacks effectively by learning the patterns of legitimate network traffic only. Moreover, our system uses Triangle Area Map which is capable of speed up the process of MCA. The effectiveness of our proposed detection system is evaluated using KDD Cup 99 dataset, and the influences of both non-normalized data and normalized data on the performance of the proposed detection system are examined.

Keywords

Denial of Service (DOS) attack, Multivariate Correlation Analysis (MCA), network traffic, normalized data, Triangle Area Map.

References

[1] V. Paxson, “Bro: A System for Detecting Network Intruders in Realtime,” Computer Networks, vol. 31, pp. 2435-2463, 1999

[2] P. Garca-Teodoro, J. Daz-Verdejo, G. Maci-Fernndez, and E. Vzquez, “Anomaly-based Network Intrusion Detection: Techniques, Systems and Challenges,” Computers & Security, vol. 28, pp. 18-28, 2009.

[3] D. E. Denning, “An Intrusion-detection Model,” IEEE Transactions on Software Engineering, pp. 222-232, 1987.

[4] K. Lee, J. Kim, K. H. Kwon, Y. Han, and S. Kim, “DDoS attack detection method using cluster analysis,” Expert Systems with Applications, vol. 34, no. 3, pp. 1659-1665, 2008.

[5] A. Tajbakhsh, M. Rahmati, and A. Mirzaei, “Intrusion detection using fuzzy association rules,” Applied Soft Computing, vol. 9, no. 2, pp. 462-469, 2009.

[6] J. Yu, H. Lee, M.-S. Kim, and D. Park, “Traffic flooding attack detection with SNMP MIB using SVM,” Computer Communications, vol. 31, no. 17, pp. 4212-4219, 2008.

[7] W. Hu, W. Hu, and S. Maybank, “AdaBoost-Based Algorithm for Network Intrusion Detection,” Trans. Sys. Man Cyber. Part B, vol. 38, no. 2, pp. 577-583, 2008.

[8] C. Yu, H. Kai, and K. Wei-Shinn, “Collaborative Detection of DDoS Attacks over Multiple Network Domains,” Parallel and Distributed Systems, IEEE Transactions on, vol. 18, pp. 1649-1662, 2007.

[9] G. Thatte, U. Mitra, and J. Heidemann, “Parametric Methods for Anomaly Detection in Aggregate Traffic,” Networking, IEEE/ACM Transactions on, vol. 19, no. 2, pp. 512-525, 2011.

[10] S. T. Sarasamma, Q. A. Zhu, and J. Huff, “Hierarchical Kohonenen Net for Anomaly Detection in Network Security,” Systems, Man, and Cybernetics, Part B: Cybernetics, IEEE Transactions on, vol. 35, pp. 302-312, 2005.

[11] S. Yu, W. Zhou, W. Jia, S. Guo, Y. Xiang, and F. Tang, “Discriminating DDoS Attacks from Flash Crowds Using Flow Correlation Coefficient,” Parallel and Distributed Systems, IEEE Transactions on, vol. 23, pp. 1073-1080, 2012.

[12] S. Jin, D. S. Yeung, and X. Wang, “Network Intrusion Detection in Covariance Feature Space,” Pattern Recognition, vol. 40, pp. 21852197, 2007.

[13] C. F. Tsai and C. Y. Lin, “A Triangle Area Based Nearest Neighbors Approach to Intrusion Detection,” Pattern Recognition, vol. 43, pp. 222-229, 2010.

[14] A. Jamdagni, Z. Tan, X. He, P. Nanda, and R. P. Liu, “RePIDS: A multi tier Real-time Payload- based Intrusion Detection System,” Computer Networks, vol. 57, pp. 811-824, 2013.

[15] Z. Tan, A. Jamdagni, X. He, P. Nanda, and R. P. Liu, “Denialof-Service Attack Detection Based on Multivariate Correlation Analysis,” Neural Information Processing, 2011, pp. 756-765.

[16] Z. Tan, A. Jamdagni, X. He, P. Nanda, and R. P. Liu, “TriangleArea-Based Multivariate Correlation Analysis for Effective Denialof-Service Attack Detection,” The 2012 IEEE 11th International Conference on Trust, Security and Privacy in Computing and Communications, Liverpool, United Kingdom, 2012, pp. 33-40.

How to cite this paper

CHAMAKURI MADHURIMA, Chintakrindi Geaya Sri, Bitra Srilatha, Jonnadula Raja Sri, Ch.Vijayananda Ratnam "DoS Attack Detection System Using Multivariate Correlation Analysis" Iconic Research And Engineering Journals Volume 1 Issue 9 2018 Page 166-170
CHAMAKURI MADHURIMA, Chintakrindi Geaya Sri, Bitra Srilatha, Jonnadula Raja Sri, Ch.Vijayananda Ratnam "DoS Attack Detection System Using Multivariate Correlation Analysis" Iconic Research And Engineering Journals, vol. 1, no. 9, Mar. 2018
CHAMAKURI MADHURIMA, Chintakrindi Geaya Sri, Bitra Srilatha, Jonnadula Raja Sri, Ch.Vijayananda Ratnam (2018). DoS Attack Detection System Using Multivariate Correlation Analysis. Iconic Research And Engineering Journals, 1(9).
CHAMAKURI MADHURIMA, Chintakrindi Geaya Sri, Bitra Srilatha, Jonnadula Raja Sri, Ch.Vijayananda Ratnam "DoS Attack Detection System Using Multivariate Correlation Analysis" Iconic Research And Engineering Journals, vol. 1, no. 9, Mar. 2018.
@article{1700357,
      author = {CHAMAKURI MADHURIMA, Chintakrindi Geaya Sri, Bitra Srilatha, Jonnadula Raja Sri, Ch.Vijayananda Ratnam},
      title = {DoS Attack Detection System Using Multivariate Correlation Analysis},
      journal = {Iconic Research And Engineering Journals},
      year = {2018},
      volume = {1},
      number = {9},
      pages = {166-170},
      issn = {2456-8880},
      url = {https://www.irejournals.com/formatedpaper/1700357.pdf},
      abstract = {There are many interconnected systems which we are working in our daily life i.e., cloud computing servers, web servers. These systems are now under the threat of various network attacks. Out of those, Denial of Service (DoS) causes serious impact to these interconnected systems. It happened so, because the server remains busy with the fake requests sent from the attackers by serving those fake requests. So, to increase the efficiency it is important to detect and prevent DoS attacks.  In this paper, we present a DoS attack detection system that uses Multivariate Correlation Analysis (MCA) for accurate network traffic characterization by extracting the geometrical correlations between network traffic features. Our MCA based DoS attack detection system uses anomaly-based detection technique to recognize the attack. This makes our solution capable of detecting known and unknown DoS attacks effectively by learning the patterns of legitimate network traffic only. Moreover, our system uses Triangle Area Map which is capable of speed up the process of MCA. The effectiveness of our proposed detection system is evaluated using KDD Cup 99 dataset, and the influences of both non-normalized data and normalized data on the performance of the proposed detection system are examined.},
      keywords = {Denial of Service (DOS) attack, Multivariate Correlation Analysis (MCA), network traffic, normalized data, Triangle Area Map.},
      month = {March},
  }