Abstract Low-rate Distributed Denial of Service (LDoS) attack is another form of DDoS attack for disrupting the cloud services. It differs from DDoS attack in terms of attack volume. DDoS attacks usually have very high attack volume; however, LDoS have very low attack rate. Moreover, these attacks are launched periodically with high narrow spike and low frequency. The behavior of the LDoS attack traffic is very much close to the behavior of the normal traffic; therefore LDoS attacks are capable to bypass the DDoS detection system. Therefore, low-rate DDoS attacks can persist for longer time and endanger the victim. LDoS attacks fraudulently consume the cloud resources for prolonged period of time which raises the economic concerns of cloud-based service providers. This paper presents an effective approach to detect the presence of LDoS attack flow in cloud computing. The proposed approach perform hypothesis test based on t-statistic to identify the LDoS attack flows. To verify the claims made in the paper and to demonstrate the effectiveness of the proposed approach, several experiments are done with the help of suitable benchmark datasets.
[1]
Gabriel Maciá-Fernández,et al.
Defense techniques for low-rate DoS attacks against application servers
,
2010,
Comput. Networks.
[2]
Wanlei Zhou,et al.
Low-Rate DDoS Attacks Detection and Traceback by Using New Information Metrics
,
2011,
IEEE Transactions on Information Forensics and Security.
[3]
Zubair A. Baig,et al.
Controlled access to cloud resources for mitigating Economic Denial of Sustainability (EDoS) attacks
,
2016,
Comput. Networks.
[4]
Douglas Jacobson,et al.
The Insecurity of Cloud Utility Models
,
2013,
IT Professional.
[5]
Kai Hwang,et al.
Collaborative detection and filtering of shrew DDoS attacks using spectral analysis
,
2006,
J. Parallel Distributed Comput..
[6]
Brij B. Gupta,et al.
Security challenges in cloud computing: state-of-art
,
2017,
Int. J. Big Data Intell..
[7]
Weifeng Chen,et al.
Flow level detection and filtering of low-rate DDoS
,
2012,
Comput. Networks.