کد مقاله | کد نشریه | سال انتشار | مقاله انگلیسی | نسخه تمام متن |
---|---|---|---|---|
5026610 | 1470625 | 2017 | 11 صفحه PDF | دانلود رایگان |

This paper analyzes network attacks using rank distribution data. Rank distributions for a number of variables generated by a single IP address are compared for normal and anomalous network states. The investigated network variables include the number of active flows, the rate of incoming TCP, UDP and ICMP traffic, as well as the frequency of references to a web server (for a given port). Experimental data were obtained during experiments performed involving a real bandwidth DDoS attack on a popular Internet portal. The rank distribution collected under normal network conditions enables the determination of threshold values for major network variables; exceeding these thresholds should therefore lead to the identification of attacking IP addresses and subsequent blocking of their access.
Journal: Procedia Engineering - Volume 201, 2017, Pages 417-427