1 Sathyabama University, Chennai, Tamil Nadu, India.
2 St. Josephs' College of Engineering, Chennai, Tamil Nadu, India.
Flooding based distributed denial of service (DDOS) attack presents a very serious threat to the stability of the Internet. In a DDoS attack, multiple malicious hosts launch a coordinated offense against one victim, which increases the resources for the offense while making it harder to track down the attackers Due to the readily available tools, “Flooding” attack becomes most common DDOS attack. They intend to over flow and consume resources available to the victim. When the number of attackers is very large, the flows from each attacker can be very small to detect. So, detection based on instantaneous deviation will be useless. Because, the deviation will be very small in small flow. So, we want a different mechanism to detect the deviation. In this paper we propose a comprehensive sequential test method to solve this problem. Over a time series, we capture deviations and sum up, which will be used to find out the deviation from a normal behavior over time. Most of the exciting systems are based Traffic volume alone. But this paper proposes the sequential hypothesis test method which is very much useful to reduce detection time and to reduce misdetection rates. It is possible to balance the trade of between the three quantities namely detection time, false alarm and misdetection rate.
DDOS attack, sequential test method, Anomaly detective