An Unsupervised Approach to DDoS Attack Detection and Mitigation in Near-Real Time

dc.contributor.authorMcandrew, Robert
dc.contributor.authorHayne, Stephen
dc.contributor.authorWang, Haonan
dc.date.accessioned2020-01-04T08:31:41Z
dc.date.available2020-01-04T08:31:41Z
dc.date.issued2020-01-07
dc.description.abstractWe present an approach for Distributed Denial of Service (DDoS) attack detection and mitigation in near-real time. The adaptive unsupervised machine learning methodology is based on volumetric thresholding, Functional Principal Component Analysis, and K-means clustering (with tuning parameters for flexibility), which dissects the dataset into categories of outlier source IP addresses. A probabilistic risk assessment technique is used to assign “threat levels” to potential malicious actors. We use our approach to analyze a synthetic DDoS attack with ground truth, as well as the Network Time Protocol (NTP) amplification attack that occurred during January of 2014 at a large mountain-range university. We demonstrate the speed and capabilities of our technique through replay of the NTP attack. We show that we can detect and attenuate the DDoS within two minutes with significantly reduced volume throughout the six waves of the attack.
dc.format.extent10 pages
dc.identifier.doi10.24251/HICSS.2020.792
dc.identifier.isbn978-0-9981331-3-3
dc.identifier.urihttp://hdl.handle.net/10125/64534
dc.language.isoeng
dc.relation.ispartofProceedings of the 53rd Hawaii International Conference on System Sciences
dc.rightsAttribution-NonCommercial-NoDerivatives 4.0 International
dc.rights.urihttps://creativecommons.org/licenses/by-nc-nd/4.0/
dc.subjectMachine Learning and Cyber Threat Intelligence and Analytics
dc.subjectddos
dc.subjectfunctional principal component analysis
dc.subjectk-means clustering
dc.subjectnetwork monitoring
dc.subjectunsupervised learning
dc.titleAn Unsupervised Approach to DDoS Attack Detection and Mitigation in Near-Real Time
dc.typeConference Paper
dc.type.dcmiText

Files

Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
0639.pdf
Size:
684.73 KB
Format:
Adobe Portable Document Format