Detecting DDoS Attacks on Multiple Network Hosts: Advanced Pattern Detection Method for the Identification of Intelligent Botnet Attacks

Detecting DDoS Attacks on Multiple Network Hosts: Advanced Pattern Detection Method for the Identification of Intelligent Botnet Attacks

Konstantinos F. Xylogiannopoulos, Panagiotis Karampelas, Reda Alhajj
Copyright: © 2021 |Pages: 15
ISBN13: 9781799853480|ISBN10: 1799853489|EISBN13: 9781799853497
DOI: 10.4018/978-1-7998-5348-0.ch005
Cite Chapter Cite Chapter

MLA

Xylogiannopoulos, Konstantinos F., et al. "Detecting DDoS Attacks on Multiple Network Hosts: Advanced Pattern Detection Method for the Identification of Intelligent Botnet Attacks." Research Anthology on Combating Denial-of-Service Attacks, edited by Information Resources Management Association, IGI Global, 2021, pp. 89-103. https://doi.org/10.4018/978-1-7998-5348-0.ch005

APA

Xylogiannopoulos, K. F., Karampelas, P., & Alhajj, R. (2021). Detecting DDoS Attacks on Multiple Network Hosts: Advanced Pattern Detection Method for the Identification of Intelligent Botnet Attacks. In I. Management Association (Ed.), Research Anthology on Combating Denial-of-Service Attacks (pp. 89-103). IGI Global. https://doi.org/10.4018/978-1-7998-5348-0.ch005

Chicago

Xylogiannopoulos, Konstantinos F., Panagiotis Karampelas, and Reda Alhajj. "Detecting DDoS Attacks on Multiple Network Hosts: Advanced Pattern Detection Method for the Identification of Intelligent Botnet Attacks." In Research Anthology on Combating Denial-of-Service Attacks, edited by Information Resources Management Association, 89-103. Hershey, PA: IGI Global, 2021. https://doi.org/10.4018/978-1-7998-5348-0.ch005

Export Reference

Mendeley
Favorite

Abstract

The proliferation of low security internet of things devices has widened the range of weapons that malevolent users can utilize in order to attack legitimate services in new ways. In the recent years, apart from very large volumetric distributed denial of service attacks, low and slow attacks initiated from intelligent bot networks have been detected to target multiple hosts in a network in a timely fashion. However, even if the attacks seem to be “innocent” at the beginning, they generate huge traffic in the network without practically been detected by the traditional DDoS attack detection methods. In this chapter, an advanced pattern detection method is presented that is able to collect and classify in real time all the incoming traffic and detect a developing slow and low DDoS attack by monitoring the traffic in all the hosts of the network. The experimental analysis on a real dataset provides useful insights about the effectiveness of the method by identifying not only the main source of attack but also secondary sources that produce low traffic, targeting though multiple hosts.

Request Access

You do not own this content. Please login to recommend this title to your institution's librarian or purchase it from the IGI Global bookstore.