Lecture Notes in Computer Science, 2006, Volume 4158/2006, 541-550, DOI: 10.1007/11839569_53

A Real-Time and Reliable Approach to Detecting Traffic Variations at Abnormally High and Low Rates

Ming Li, Shengquan Wang and Wei Zhao

View Related Documents

Abstract

Abnormal variations of traffic are conventionally considered to occur under the condition that traffic rate is abnormally high in the cases, such as traffic congestions or traffic under distributed denial-of-service (DDOS) flood attacks. Various methods in detecting traffic variations at abnormally high rate have been reported. We note that a recent paper by Kuzmanovic and Knightly, which explains a type of DDOS attacks that may result in abnormally low traffic rate. Such a type of abnormal variations of traffic, therefore, can easily evade from detection systems based on abnormally high traffic rate. This paper presents a real-time and reliable detection approach to detect traffic variations at both abnormally high and low rates. The formulas in terms of detection probabilities, miss probabilities, classification criterion, and detection thre-sholds are proposed.

Keywords  Anomaly detection - real-time detection - reliable detection - traffic constraint

Fulltext Preview

Image of the first page of the fulltext document