Evaluation of Takagi-Sugeno-Kang fuzzy method in entropy-based detection of DDoS attacks
Computer Science and Information Systems, Tome 15 (2018) no. 1.

Voir la notice de l'article provenant de la source Computer Science and Information Systems website

The detection of distributed denial of service (DDoS) attacks based on internet traffic anomalies is a method which is general in nature and can detect unknown or zero-day attacks. One of the statistical characteristics used for this purpose is network traffic entropy: a sudden change in entropy may indicate a DDoS attack. However, this approach often gives false positives, and this is the main obstacle to its wider deployment within network security equipment. In this paper, we propose a new, two-step method for detection of DDoS attacks. This method combines the approaches of network traffic entropy and the Takagi-Sugeno-Kang fuzzy system. In the first step, the detection process calculates the entropy distribution of the network packets. In the second step, the Takagi-Sugeno-Kang fuzzy system (TSK-FS) method is applied to these entropy values. The performance of the TSK-FS method is compared with that of the typically used approach, in which cumulative sum (CUSUM) change point detection is applied directly to entropy time series. The results show that the TSK-FS DDoS detector reaches enhanced sensitivity and robustness in the detection process, achieving a high true-positive detection rate and a very low false-positive rate. As it is based on entropy, this combined method retains its generality and is capable of detecting various types of attack.
Keywords: Network security; Fuzzy neural networks; Distributed denial of service attacks; Intrusion detection; Takagi-Sugeno-Kang model
@article{CSIS_2018_15_1_a6,
     author = {Miodrag Petkovic and Ilija Basicevic and Dragan Kukolj and Miroslav Popovic},
     title = {Evaluation of {Takagi-Sugeno-Kang} fuzzy method in entropy-based detection of {DDoS} attacks},
     journal = {Computer Science and Information Systems},
     publisher = {mathdoc},
     volume = {15},
     number = {1},
     year = {2018},
     url = {http://geodesic.mathdoc.fr/item/CSIS_2018_15_1_a6/}
}
TY  - JOUR
AU  - Miodrag Petkovic
AU  - Ilija Basicevic
AU  - Dragan Kukolj
AU  - Miroslav Popovic
TI  - Evaluation of Takagi-Sugeno-Kang fuzzy method in entropy-based detection of DDoS attacks
JO  - Computer Science and Information Systems
PY  - 2018
VL  - 15
IS  - 1
PB  - mathdoc
UR  - http://geodesic.mathdoc.fr/item/CSIS_2018_15_1_a6/
ID  - CSIS_2018_15_1_a6
ER  - 
%0 Journal Article
%A Miodrag Petkovic
%A Ilija Basicevic
%A Dragan Kukolj
%A Miroslav Popovic
%T Evaluation of Takagi-Sugeno-Kang fuzzy method in entropy-based detection of DDoS attacks
%J Computer Science and Information Systems
%D 2018
%V 15
%N 1
%I mathdoc
%U http://geodesic.mathdoc.fr/item/CSIS_2018_15_1_a6/
%F CSIS_2018_15_1_a6
Miodrag Petkovic; Ilija Basicevic; Dragan Kukolj; Miroslav Popovic. Evaluation of Takagi-Sugeno-Kang fuzzy method in entropy-based detection of DDoS attacks. Computer Science and Information Systems, Tome 15 (2018) no. 1. http://geodesic.mathdoc.fr/item/CSIS_2018_15_1_a6/