search menu icon-carat-right cmu-wordmark

Detecting Distributed Attacks using Network-Wide Flow Traffic

White Paper
In this paper, the authors present their methods for detecting distributed attacks in backbone networks using sampled flow traffic data.
Publisher

Software Engineering Institute

Abstract

In this paper, presented at FloCon 2005, we present our methods to detect distributed attacks in backbone networks using sampled flow traffic data. Distributed attacks are traditionally viewed to be fundamentally more difficult to detect than single-source attacks. In contrast, we demonstrate that the more distributed an attack is, the better our methods are at detecting it. This is because our methods analyze correlations across all network-wide traffic simultaneously, instead of inspecting traffic on individual links in isolation. In addition, our methods are highly sensitive to the attack intensity; we show that attacks rates of less than 1% of the underlying traffic can be detected successfully by our methods.

Part of a Collection

FloCon 2005 Collection

This content was created for a conference series or symposium and does not necessarily reflect the positions and views of the Software Engineering Institute.