DDoS detection method based on the technical analysis used in the stock market

주식시장 기술 분석 기법을 활용한 DDoS 탐지 방법

  • 윤정훈 (LG-Dacom 기술연구원) ;
  • 정송 (EECS, KAIST, Network Systems 연구실)
  • Published : 2009.08.27

Abstract

We propose a method for detecting DDoS (Distributed Denial of Service) traffic in real-time inside the backbone network. For this purpose, we borrow the concepts of MACD (Moving Average Convergence Divergence) and RoC (Rate of Change), which are used for technical analysis in the stock market Due to the fact that the method is based on a quantitative, rather than a heuristic, detection level, DDoS traffic can be detected with greater accuracy (by reducing the false alarm ratio). Through simulation results, we show how the detection level is determined and demonstrate how much the accuracy of detection is enhanced.

Keywords