DETECTION OF DIFFERENT TYPES OF DISTRIBUTED DENIAL OF SERVICE ATTACKS USING MULTIPLE FEATURES OF ENTROPY AND SEQUENTIAL PROBABILITIES RATIO TEST

Distributed Denial of Service (DDoS) is the most dangerous attacks that targeted public servers. It is difficult for victims to detect these kinds of attacks because DDoS attacks can be done remotely and reflected by legal users in the network toward specific victim. The goal of this research is to...

Full description

Bibliographic Details
Published in:Journal of Engineering Science and Technology
Main Author: Ali B.H.; Sulaiman N.; Al-Haddad S.A.R.; Atan R.; Hassan S.L.M.
Format: Article
Language:English
Published: Taylor's University 2023
Online Access:https://www.scopus.com/inward/record.uri?eid=2-s2.0-85152915864&partnerID=40&md5=75225f587bd921c27f65d88649713e76
id 2-s2.0-85152915864
spelling 2-s2.0-85152915864
Ali B.H.; Sulaiman N.; Al-Haddad S.A.R.; Atan R.; Hassan S.L.M.
DETECTION OF DIFFERENT TYPES OF DISTRIBUTED DENIAL OF SERVICE ATTACKS USING MULTIPLE FEATURES OF ENTROPY AND SEQUENTIAL PROBABILITIES RATIO TEST
2023
Journal of Engineering Science and Technology
18
2

https://www.scopus.com/inward/record.uri?eid=2-s2.0-85152915864&partnerID=40&md5=75225f587bd921c27f65d88649713e76
Distributed Denial of Service (DDoS) is the most dangerous attacks that targeted public servers. It is difficult for victims to detect these kinds of attacks because DDoS attacks can be done remotely and reflected by legal users in the network toward specific victim. The goal of this research is to locate compromised interface and identify different types of DDoS attacks, especially up-to-date kinds of them. Multiple features of Entropy and Sequential Probabilities Ratio Test approach (E-SPRT) was proposed and implemented in order to detect different types of DDoS attacks. CICFlowMeter was used to produce bidirectional network flows and extract 82 of different features from each flow. Multiple features of E-SPRT divide incoming flows into fixed groups that have same number of flows called window size. CICDDoS2019 dataset was chosen in this research because it contains various kinds of recent attacks. The performance of all features of E-SPRT were tested by confusion matrix and compared with other higher-accuracy techniques. Finally, the implemented model with different features detects most up to date DDoS attacks and achieves an accuracy and detection rate almost over 99%. © School of Engineering, Taylor’s University.
Taylor's University
18234690
English
Article

author Ali B.H.; Sulaiman N.; Al-Haddad S.A.R.; Atan R.; Hassan S.L.M.
spellingShingle Ali B.H.; Sulaiman N.; Al-Haddad S.A.R.; Atan R.; Hassan S.L.M.
DETECTION OF DIFFERENT TYPES OF DISTRIBUTED DENIAL OF SERVICE ATTACKS USING MULTIPLE FEATURES OF ENTROPY AND SEQUENTIAL PROBABILITIES RATIO TEST
author_facet Ali B.H.; Sulaiman N.; Al-Haddad S.A.R.; Atan R.; Hassan S.L.M.
author_sort Ali B.H.; Sulaiman N.; Al-Haddad S.A.R.; Atan R.; Hassan S.L.M.
title DETECTION OF DIFFERENT TYPES OF DISTRIBUTED DENIAL OF SERVICE ATTACKS USING MULTIPLE FEATURES OF ENTROPY AND SEQUENTIAL PROBABILITIES RATIO TEST
title_short DETECTION OF DIFFERENT TYPES OF DISTRIBUTED DENIAL OF SERVICE ATTACKS USING MULTIPLE FEATURES OF ENTROPY AND SEQUENTIAL PROBABILITIES RATIO TEST
title_full DETECTION OF DIFFERENT TYPES OF DISTRIBUTED DENIAL OF SERVICE ATTACKS USING MULTIPLE FEATURES OF ENTROPY AND SEQUENTIAL PROBABILITIES RATIO TEST
title_fullStr DETECTION OF DIFFERENT TYPES OF DISTRIBUTED DENIAL OF SERVICE ATTACKS USING MULTIPLE FEATURES OF ENTROPY AND SEQUENTIAL PROBABILITIES RATIO TEST
title_full_unstemmed DETECTION OF DIFFERENT TYPES OF DISTRIBUTED DENIAL OF SERVICE ATTACKS USING MULTIPLE FEATURES OF ENTROPY AND SEQUENTIAL PROBABILITIES RATIO TEST
title_sort DETECTION OF DIFFERENT TYPES OF DISTRIBUTED DENIAL OF SERVICE ATTACKS USING MULTIPLE FEATURES OF ENTROPY AND SEQUENTIAL PROBABILITIES RATIO TEST
publishDate 2023
container_title Journal of Engineering Science and Technology
container_volume 18
container_issue 2
doi_str_mv
url https://www.scopus.com/inward/record.uri?eid=2-s2.0-85152915864&partnerID=40&md5=75225f587bd921c27f65d88649713e76
description Distributed Denial of Service (DDoS) is the most dangerous attacks that targeted public servers. It is difficult for victims to detect these kinds of attacks because DDoS attacks can be done remotely and reflected by legal users in the network toward specific victim. The goal of this research is to locate compromised interface and identify different types of DDoS attacks, especially up-to-date kinds of them. Multiple features of Entropy and Sequential Probabilities Ratio Test approach (E-SPRT) was proposed and implemented in order to detect different types of DDoS attacks. CICFlowMeter was used to produce bidirectional network flows and extract 82 of different features from each flow. Multiple features of E-SPRT divide incoming flows into fixed groups that have same number of flows called window size. CICDDoS2019 dataset was chosen in this research because it contains various kinds of recent attacks. The performance of all features of E-SPRT were tested by confusion matrix and compared with other higher-accuracy techniques. Finally, the implemented model with different features detects most up to date DDoS attacks and achieves an accuracy and detection rate almost over 99%. © School of Engineering, Taylor’s University.
publisher Taylor's University
issn 18234690
language English
format Article
accesstype
record_format scopus
collection Scopus
_version_ 1809677888176259072