{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/49735"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/49735","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"Monitoring unknown source IP addresses and packet sizes to detect DDoS attacks","abstract":"This thesis presents three procedures to detect Distributed Denial of Service (DDoS) attacks. DDoS attacks are known as one of the most expensive and destructive Internet threats. Assuming network tra c is a marked Poisson process, two parametric detection models are developed. The arrival of packet ows is modeled as Poisson process with cluster sizes that follows a mixture of discrete and heavy tailed distributions. Both detection systems monitor the percentage of unknown source IP addresses. The rst detection model is formulated as a xed sample size binary hypothesis testing. The decision making is based on the Neyman-Pearson criteria. The second parametric model is a sequential probability ratio test where the sample size is a random variable. Acceptance and rejection boundaries are deduced based on Wald's Fundamental Identity. Given that parametric distributions may fail to capture the complex and dynamic nature of the Internet, a third non-parametric detection model is proposed. In addition to the percentage of unknown source IP addresses, a second test statistic is introduced. The latter represents the mean to standard deviation ratio of data packet sizes. The Neyman-Pearson threshold is estimated from the empirical distribution functions of both random variables.","abstract_html":"This thesis presents three procedures to detect Distributed Denial of Service (DDoS) attacks. DDoS attacks are known as one of the most expensive and destructive Internet threats. Assuming network tra c is a marked Poisson process, two parametric detection models are developed. The arrival of packet ows is modeled as Poisson process with cluster sizes that follows a mixture of discrete and heavy tailed distributions. Both detection systems monitor the percentage of unknown source IP addresses. The rst detection model is formulated as a xed sample size binary hypothesis testing. The decision making is based on the Neyman-Pearson criteria. The second parametric model is a sequential probability ratio test where the sample size is a random variable. Acceptance and rejection boundaries are deduced based on Wald&#x27;s Fundamental Identity. Given that parametric distributions may fail to capture the complex and dynamic nature of the Internet, a third non-parametric detection model is proposed. In addition to the percentage of unknown source IP addresses, a second test statistic is introduced. The latter represents the mean to standard deviation ratio of data packet sizes. The Neyman-Pearson threshold is estimated from the empirical distribution functions of both random variables.","abstract_has_math":false,"creators":["Kone, Roseline"],"institution":"University of Illinois at Urbana-Champaign","degree_name":"Ph.D.","degree_level":"Dissertation","degree_discipline":"Industrial Engineering","degree_department":null,"school":null,"contributors":["Sowers, Richard B.","Abbas, Ali E.","Kiyavash, Negar","Song, Renming"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2014,"date_issued":"2014-05-30T17:07:05Z","date_published":"2014-05-30T17:07:05Z","updated_at":"2026-07-22T22:25:40Z","subjects":["Poisson Cluster Process","Compound Pareto Distribution","Binary Hypothesis Testing","Sequential Detection","Distributed Denial of Service (DDoS) Attacks"],"languages":["en"],"rights":["Copyright 2014 Roseline Estelle Sindolmane Kone"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"http://hdl.handle.net/2142/49735","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Sowers, Richard B.","Abbas, Ali E.","Kiyavash, Negar","Song, Renming"]},{"key":"dc:creator","label":"Author","values":["Kone, Roseline"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2014-05-30T17:07:05Z","2016-09-22T20:59:27Z","2014-05"]},{"key":"dc:type","label":"Dc Type","values":["text"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Industrial Engineering"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Dissertation"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Ph.D."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Poisson Cluster Process","Compound Pareto Distribution","Binary Hypothesis Testing","Sequential Detection","Distributed Denial of Service (DDoS) Attacks"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2014 Roseline Estelle Sindolmane Kone"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["http://hdl.handle.net/2142/49735"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["This thesis presents three procedures to detect Distributed Denial of Service (DDoS) attacks. DDoS attacks are known as one of the most expensive and destructive Internet threats. Assuming network tra c is a marked Poisson process, two parametric detection models are developed. The arrival of packet ows is modeled as Poisson process with cluster sizes that follows a mixture of discrete and heavy tailed distributions. Both detection systems monitor the percentage of unknown source IP addresses. The rst detection model is formulated as a xed sample size binary hypothesis testing. The decision making is based on the Neyman-Pearson criteria. The second parametric model is a sequential probability ratio test where the sample size is a random variable. Acceptance and rejection boundaries are deduced based on Wald's Fundamental Identity. Given that parametric distributions may fail to capture the complex and dynamic nature of the Internet, a third non-parametric detection model is proposed. In addition to the percentage of unknown source IP addresses, a second test statistic is introduced. The latter represents the mean to standard deviation ratio of data packet sizes. The Neyman-Pearson threshold is estimated from the empirical distribution functions of both random variables.","Item withdrawn by Mark Zulauf (zulauf@illinois.edu) on 2014-04-23T18:00:19Z Item was in collections: University of Illinois Theses & Dissertations (ID: 1) No. of bitstreams: 2 Kone_Estelle.pdf: 1904919 bytes, checksum: b4b350e1618c4fd2445fbf1276a6352b (MD5) Kone_Estelle.zip: 1200829 bytes, checksum: 3364b2849e9e39756eb130816ee96d59 (MD5)","Made available in DSpace on 2014-05-30T17:07:05Z (GMT). No. of bitstreams: 3 Roseline_Kone.pdf: 1904919 bytes, checksum: b4b350e1618c4fd2445fbf1276a6352b (MD5) Kone_Estelle.zip: 1200829 bytes, checksum: 3364b2849e9e39756eb130816ee96d59 (MD5) license.txt: 4060 bytes, checksum: 53232e683498250f19800e67353cd882 (MD5)","Item marked as restricted to the 'UIUC Users [automated]' Group (id=2) by Seth Robbins (robbins.sd@gmail.com) on 2014-05-30T17:09:55Z Item is restricted until 2016-05-30T17:09:03Z","Restriction data tranferred 2014-07-01T11:39:17-05:00 Original Data Group with Access UIUC Users [automated] Release Date: 2016-05-30 12:09:03 UTC Reason: Author requested U of Illinois access only (OA after 2yrs) in Vireo ETD system","U of I Only Restriction Lifted for Item 49786 on 2016-09-22T20:59:27Z."]},{"key":"dc:title","label":"Title","values":["Monitoring unknown source IP addresses and packet sizes to detect DDoS attacks"]}]}],"canonical_facts":{"dc:contributor":["Sowers, Richard B.","Abbas, Ali E.","Kiyavash, Negar","Song, Renming"],"dc:creator":["Kone, Roseline"],"dc:date":["2014-05-30T17:07:05Z","2016-09-22T20:59:27Z","2014-05"],"dc:description":["This thesis presents three procedures to detect Distributed Denial of Service (DDoS) attacks. DDoS attacks are known as one of the most expensive and destructive Internet threats. Assuming network tra c is a marked Poisson process, two parametric detection models are developed. The arrival of packet ows is modeled as Poisson process with cluster sizes that follows a mixture of discrete and heavy tailed distributions. Both detection systems monitor the percentage of unknown source IP addresses. The rst detection model is formulated as a xed sample size binary hypothesis testing. The decision making is based on the Neyman-Pearson criteria. The second parametric model is a sequential probability ratio test where the sample size is a random variable. Acceptance and rejection boundaries are deduced based on Wald's Fundamental Identity. Given that parametric distributions may fail to capture the complex and dynamic nature of the Internet, a third non-parametric detection model is proposed. In addition to the percentage of unknown source IP addresses, a second test statistic is introduced. The latter represents the mean to standard deviation ratio of data packet sizes. The Neyman-Pearson threshold is estimated from the empirical distribution functions of both random variables.","Item withdrawn by Mark Zulauf (zulauf@illinois.edu) on 2014-04-23T18:00:19Z Item was in collections: University of Illinois Theses & Dissertations (ID: 1) No. of bitstreams: 2 Kone_Estelle.pdf: 1904919 bytes, checksum: b4b350e1618c4fd2445fbf1276a6352b (MD5) Kone_Estelle.zip: 1200829 bytes, checksum: 3364b2849e9e39756eb130816ee96d59 (MD5)","Made available in DSpace on 2014-05-30T17:07:05Z (GMT). No. of bitstreams: 3 Roseline_Kone.pdf: 1904919 bytes, checksum: b4b350e1618c4fd2445fbf1276a6352b (MD5) Kone_Estelle.zip: 1200829 bytes, checksum: 3364b2849e9e39756eb130816ee96d59 (MD5) license.txt: 4060 bytes, checksum: 53232e683498250f19800e67353cd882 (MD5)","Item marked as restricted to the 'UIUC Users [automated]' Group (id=2) by Seth Robbins (robbins.sd@gmail.com) on 2014-05-30T17:09:55Z Item is restricted until 2016-05-30T17:09:03Z","Restriction data tranferred 2014-07-01T11:39:17-05:00 Original Data Group with Access UIUC Users [automated] Release Date: 2016-05-30 12:09:03 UTC Reason: Author requested U of Illinois access only (OA after 2yrs) in Vireo ETD system","U of I Only Restriction Lifted for Item 49786 on 2016-09-22T20:59:27Z."],"dc:identifier":["http://hdl.handle.net/2142/49735"],"dc:language":["en"],"dc:rights":["Copyright 2014 Roseline Estelle Sindolmane Kone"],"dc:subject":["Poisson Cluster Process","Compound Pareto Distribution","Binary Hypothesis Testing","Sequential Detection","Distributed Denial of Service (DDoS) Attacks"],"dc:title":["Monitoring unknown source IP addresses and packet sizes to detect DDoS attacks"],"dc:type":["text"],"thesis:degree_discipline":["Industrial Engineering"],"thesis:degree_level":["Dissertation"],"thesis:degree_name":["Ph.D."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:25:40Z"}