Skip to Main Content (Press Enter)

Logo CNR
  • ×
  • Home
  • Persone
  • Pubblicazioni
  • Strutture
  • Competenze

UNI-FIND
Logo CNR

|

UNI-FIND

cnr.it
  • ×
  • Home
  • Persone
  • Pubblicazioni
  • Strutture
  • Competenze
  1. Pubblicazioni

A Similarity Based Approach for Application DoS Attacks Detection

Contributo in Atti di convegno
Data di Pubblicazione:
2013
Abstract:
The ability to identify anomalous traffic patterns is a central issue for network managers: primarily lots of problems could arise from network attacks, such as viruses and tunneling tools. In this paper we present a detection algorithm able to extract information analyzing features of the network traffic containing attacks. The algorithm exploits statistical methodologies for traffic categorization. To assess the practical usability of the proposed algorithms we have tested its application in a case of abuse of resources through an application DoS attack known as slowloris. We have obtained an excellent reliability both analyzing single samples of traffic (100% of anomalies detection, with 1% probability of false positives) and processing multiple samples, through an average measurement (100% of anomalies detection, with a distance between traffics of 5.29 sigma, providing an extremely low false positive error rate).
Tipologia CRIS:
04.01 Contributo in Atti di convegno
Keywords:
anomaly based detection; network traffic characterization; slow dos attack
Elenco autori:
Cambiaso, Enrico; Aiello, Maurizio; Scaglione, Silvia; Papaleo, Gianluca
Autori di Ateneo:
AIELLO MAURIZIO
CAMBIASO ENRICO
SCAGLIONE SILVIA
Link alla scheda completa:
https://iris.cnr.it/handle/20.500.14243/295167
Pubblicato in:
PROCEEDINGS - IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS
Series
  • Dati Generali

Dati Generali

URL

http://ieeexplore.ieee.org/xpls/icp.jsp?arnumber=6754984
  • Utilizzo dei cookie

Realizzato con VIVO | Designed by Cineca | 26.5.0.0 | Sorgente dati: PREPROD (Ribaltamento disabilitato)