Show simple item record

dc.contributor.authorSiracusano, M
dc.contributor.authorShiaeles, S
dc.contributor.authorGhita, B
dc.date.accessioned2019-07-28T01:07:21Z
dc.date.available2019-07-28T01:07:21Z
dc.date.issued2019-02-07
dc.identifier.isbn9781538672723
dc.identifier.issn2150-329X
dc.identifier.issn2150-329X
dc.identifier.urihttp://hdl.handle.net/10026.1/14704
dc.description.abstract

Low-rate application layer distributed denial of service (LDDoS) attacks are both powerful and stealthy. They force vulnerable webservers to open all available connections to the adversary, denying resources to real users. Mitigation advice focuses on solutions that potentially degrade quality of service for legitimate connections. Furthermore, without accurate detection mechanisms, distributed attacks can bypass these defences. A methodology for detection of LDDoS attacks, based on characteristics of malicious TCP flows, is proposed within this paper. Research will be conducted using combinations of two datasets: one generated from a simulated network, the other from the publically available CIC DoS dataset. Both contain the attacks slowread, slowheaders and slowbody, alongside legitimate web browsing. TCP flow features are extracted from all connections. Experimentation was carried out using six supervised AI algorithms to categorise attack from legitimate flows. Decision trees and kNN accurately classified up to 99.99% of flows, with exceptionally low false positive and false negative rates, demonstrating the potential of AI in LDDoS detection.

dc.format.extent1-6
dc.language.isoen
dc.publisherIEEE
dc.subjectDoS
dc.subjectLDoS
dc.subjectLDDoS
dc.subjectDistributed Denial of Service
dc.subjectLow rate attack
dc.subjectRoQ
dc.subjectArtificial Intelligence
dc.subjectNetwork Defence
dc.subjectMachine Learning
dc.subjectDeep Learning
dc.subjectComputer Security
dc.subjectCyber Security
dc.titleDetection of LDDoS Attacks Based on TCP Connection Parameters
dc.typeconference
dc.typeProceedings Paper
plymouth.author-urlhttp://arxiv.org/abs/1904.01508v1
plymouth.date-start2018-10-23
plymouth.date-finish2018-10-25
plymouth.volume00
plymouth.publisher-urlhttp://dx.doi.org/10.1109/GIIS.2018.8635701
plymouth.conference-name2018 Global Information Infrastructure and Networking Symposium (GIIS)
plymouth.publication-statusPublished
plymouth.journal2018 Global Information Infrastructure and Networking Symposium (GIIS)
dc.identifier.doi10.1109/giis.2018.8635701
plymouth.organisational-group/Plymouth
plymouth.organisational-group/Plymouth/Faculty of Science and Engineering
plymouth.organisational-group/Plymouth/Faculty of Science and Engineering/School of Engineering, Computing and Mathematics
plymouth.organisational-group/Plymouth/REF 2021 Researchers by UoA
plymouth.organisational-group/Plymouth/REF 2021 Researchers by UoA/UoA11 Computer Science and Informatics
plymouth.organisational-group/Plymouth/Users by role
plymouth.organisational-group/Plymouth/Users by role/Academics
dcterms.dateAccepted2019-02-01
dc.rights.embargodate2020-7-3
dc.identifier.eissn2150-329X
dc.rights.embargoperiodNot known
rioxxterms.versionAccepted Manuscript
rioxxterms.versionofrecord10.1109/giis.2018.8635701
rioxxterms.licenseref.urihttp://www.rioxx.net/licenses/all-rights-reserved
rioxxterms.licenseref.startdate2019-02-07
rioxxterms.typeConference Paper/Proceeding/Abstract
plymouth.funderCyber-Trust: Advanced Cyber-Threat Intelligence, Detection, and Mitigation Platform for a Trusted Internet of Things::European Commision - H2020 RIA


Files in this item

Thumbnail
Thumbnail

This item appears in the following Collection(s)

Show simple item record


All items in PEARL are protected by copyright law.
Author manuscripts deposited to comply with open access mandates are made available in accordance with publisher policies. Please cite only the published version using the details provided on the item record or document. In the absence of an open licence (e.g. Creative Commons), permissions for further reuse of content should be sought from the publisher or author.
Theme by 
Atmire NV