Back to results

University of Illinois at Urbana-Champaign

Monitoring unknown source IP addresses and packet sizes to detect DDoS attacks

Abstract

dc:description

This thesis presents three procedures to detect Distributed Denial of Service (DDoS) attacks. DDoS attacks are known as one of the most expensive and destructive Internet threats. Assuming network tra c is a marked Poisson process, two parametric detection models are developed. The arrival of packet ows is modeled as Poisson process with cluster sizes that follows a mixture of discrete and heavy tailed distributions. Both detection systems monitor the percentage of unknown source IP addresses. The rst detection model is formulated as a xed sample size binary hypothesis testing. The decision making is based on the Neyman-Pearson criteria. The second parametric model is a sequential probability ratio test where the sample size is a random variable. Acceptance and rejection boundaries are deduced based on Wald's Fundamental Identity. Given that parametric distributions may fail to capture the complex and dynamic nature of the Internet, a third non-parametric detection model is proposed. In addition to the percentage of unknown source IP addresses, a second test statistic is introduced. The latter represents the mean to standard deviation ratio of data packet sizes. The Neyman-Pearson threshold is estimated from the empirical distribution functions of both random variables.

Degree

thesis:*
Name thesis:degree_name
Ph.D.
Level thesis:degree_level
Dissertation
Discipline thesis:degree_discipline
Industrial Engineering
Grantor
University of Illinois at Urbana-Champaign
Year dc:date
2014

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Kone, Roseline
Contributors dc:contributor
  • Sowers, Richard B.
  • Abbas, Ali E.
  • Kiyavash, Negar
  • Song, Renming

Subjects

dc:subject × 5

Rights

dc:rights
Statement dc:rights
  • Copyright 2014 Roseline Estelle Sindolmane Kone
Language dc:language
en

Identifiers

dc:identifier.*
Handle dc:identifier
http://hdl.handle.net/2142/49735
OAI identifier oai:identifier
oai:www.ideals.illinois.edu:2142/49735

Chain of custody

source
Harvested from
University of Illinois - Urbana-Champaign
Base URL
www.ideals.illinois.edu/oai-pmh
Last updated
2026-07-22
Source record
OAI-PMH GetRecord
citation

Kone, Roseline. Monitoring unknown source IP addresses and packet sizes to detect DDoS attacks. Dissertation thesis, University of Illinois at Urbana-Champaign, 2014. http://hdl.handle.net/2142/49735