作者
Vincenzo Matta, Mario Di Mauro, Maurizio Longo
发表日期
2017/8/28
研讨会论文
2017 25th European Signal Processing Conference (EUSIPCO)
页码范围
2171-2175
出版商
IEEE
简介
In a randomized DDoS attack with increasing emulation dictionary, the bots try to hide their malicious activity by disguising their traffic patterns as "normal" traffic patterns. In this work, we extend the DDoS class introduced in [1], [2] to the case of a multi-clustered botnet, whose main feature is that the emulation dictionary is split over the botnet, giving rise to multiple botnet clusters. We propose two strategies to identify the botnet in such challenging scenario, one based on cluster expurgation, the other one on a union rule. Consistency of both algorithms under ideal conditions is ascertained, while their performance is examined over real network traces.
引用总数
20182019202020212022202341754
学术搜索中的文章
V Matta, M Di Mauro, M Longo - 2017 25th European Signal Processing Conference …, 2017