Skip to main content

Multiple Clustering Method for Real-Time Distributed Denial-of-Service Attack Detection

  • Conference paper
  • First Online:
Proceedings of Integrated Intelligence Enable Networks and Computing

Abstract

Recent research in networking attacks shows that the distributed denial-of-service (DDoS) attack is increase by 19% in last year. The DDoS attack is performed by flooding packets from various distributed bots nodes to victim server from attacker. Detection of distributed denial-of-service attack is challenging tasks due to availability of high-computational resources and technology. This paper proposes the multiple clustering methods for DDoS attack detection. The hierarchical and K-means with PCA clustering convert the unlabeled data traffic into labeled data traffic. The K-nearest neighbors, SVM, logistic regression, and random forest classification are used to classify labeled data traffic into normal and DDoS attack traffics. The proposed method is validated using KDD CUP dataset. The proposed method gives high accuracy and reduces false rate as compared to existing methods.

This is a preview of subscription content, log in via an institution to check access.

Access this chapter

Subscribe and save

Springer+ Basic
$34.99 /Month
  • Get 10 units per month
  • Download Article/Chapter or eBook
  • 1 Unit = 1 Article or 1 Chapter
  • Cancel anytime
Subscribe now

Buy Now

Chapter
USD 29.95
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
eBook
USD 169.00
Price excludes VAT (USA)
  • Available as EPUB and PDF
  • Read on any device
  • Instant download
  • Own it forever
Softcover Book
USD 219.99
Price excludes VAT (USA)
  • Compact, lightweight edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info
Hardcover Book
USD 219.99
Price excludes VAT (USA)
  • Durable hardcover edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Purchases are for personal use only

Institutional subscriptions

Similar content being viewed by others

References

  1. S. Miller, C. Busby-Earle, ‘The role of machine learning in botnet detection, in 2016 11th International Conference for Internet Technology and Secured Transactions (ICITST), pp. 359–364 (2016)

    Google Scholar 

  2. M. Aamir, S.M.A. Zaidi, Clustering based Semi-supervised machine learning for DDoS attack classification. J. King Saud Univ. Comput. Inf. Sci. (2019)

    Google Scholar 

  3. S. Fitriani, S. Mandala, M.A. Murti, Review of semi-supervised method for intrusion detection system, in Asia Pacific Conference on Multimedia and Broadcasting (APMediaCast), pp. 36–41 (2016)

    Google Scholar 

  4. Y. Gu, Y. Wang, Z. Yang, F. Xiong, Y. Gao, Multiple-features-based semisupervised clustering DDoS detection method. Math. Problems Eng. (2017)

    Google Scholar 

  5. R. Zhong, G. Yue, DDoS detection system based on data mining, in Proceedings of 2nd International Symposium on Networking and Network Security, Jinggang Shan, China, pp. 062–065, 2–4 Apr 2010

    Google Scholar 

  6. M. Jonker, A. King, J. Krupp, C. Rossow, A. Sperotto, A. Dainotti, Millions of targets under attack: a macroscopic characterization of the DoS ecosystem, in Proceedings of the 2017 Internet Measurement Conference, pp. 100–113 (2017)

    Google Scholar 

  7. J. Wu, X. Wang, X. Lee, B. Yan, Detecting DDoS attack towards DNS server using a neural network classifier, in International Conference on Artificial Neural Networks, pp. 118–123 (Springer, Berlin, 2010)

    Google Scholar 

  8. J. Kim, A. Sim, B. Tierney, S. Suh, I. Kim, Multivariate network traffic analysis using clustered patterns. Computing, pp. 1–23 (2018)

    Google Scholar 

  9. X. Zhu, Semi-supervised Learning Literature Survey. Computer Science, University Wisconsin-Madison 2(3) (2006)

    Google Scholar 

  10. G. Xiang, W. Min, ‘Applying Semi-supervised cluster algorithm for anomaly detection, in 2010 Third International Symposium on Information Processing (ISIP), pp. 43–45 (2010)

    Google Scholar 

  11. H. Beitollahi, G. Deconinck, Analyzing well-known countermeasures against distributed denial of service attacks. Comput. Commun. 35(11), 1312–1332 (2012)

    Article  Google Scholar 

  12. M. Wang, Y. Lu, J. Qin, A dynamic MLP-based DDoS attack detection method using feature selection and feedback. Comput. Secur. 88, 101645 (2020)

    Article  Google Scholar 

  13. S. Soheily-Khah, P.-F. Marteau, N. Béchet, Intrusion detection in network systems through hybrid supervised and unsupervised machine learning process: a case study on the ISCX dataset, in 2018 1st International Conference on Data Intelligence and Security (ICDIS), pp. 219–226 (2018)

    Google Scholar 

  14. M. Idhammad, K. Afdel, M. Belouch, Semi-supervised machine learning approach for DDoS detection. Appl. Intell. pp. 1–1 (2018)

    Google Scholar 

  15. K. Kato, V. Klyuev, Development of a network intrusion detection system using Apache Hadoop and Spark, in IEEE Conference on Dependable and Secure Computing, pp. 416–423 (2017)

    Google Scholar 

  16. A.S. Boroujerdi, S. Ayat, A robust ensemble of neuro-fuzzy classifiers for DDoS attack detection, in 2013 3rd International Conference on Computer Science and Network Technology (ICCSNT), pp. 484–487 (2013)

    Google Scholar 

  17. J. François, I. Aib, R. Boutaba, FireCol: a collaborative protection network for the detection of flooding DDoS attacks. IEEE/ACM Trans. Netw. (TON) 20, 1828–1841 (2012)

    Article  Google Scholar 

  18. B. Jia, Y. Ma, X. Huang, Z. Lin, Y. Sun, A novel real time DDoS attack detection mechanishm based on MDRA algorithm in big data. Hindawi Publishing Corporation Math. Probl. Eng. Vol. 2016

    Google Scholar 

  19. A. Scherrer, N. Larrieu, P. Owezarski, P. Borgnat, P. Abry, Non-Gaussian and long memory statistical characterizations for Internet traffic with anomalies. IEEE Trans. Dependable Secure Comput. 4(1), 56–70 (2007)

    Article  Google Scholar 

  20. Z.Y. Tan, A. Jamdagni, X.J. He, P. Nanda, R.P. Liu, A system for denial-of-service attack detection based on multivariate correlation analysis. IEEE Trans. Parallel Distrib. Syst. 25(2), 447–456 (2014)

    Article  Google Scholar 

Download references

Author information

Authors and Affiliations

Authors

Corresponding author

Correspondence to Girish Talmale .

Editor information

Editors and Affiliations

Rights and permissions

Reprints and permissions

Copyright information

© 2021 The Author(s), under exclusive license to Springer Nature Singapore Pte Ltd.

About this paper

Check for updates. Verify currency and authenticity via CrossMark

Cite this paper

Talmale, G., Shrawankar, U. (2021). Multiple Clustering Method for Real-Time Distributed Denial-of-Service Attack Detection. In: Singh Mer, K.K., Semwal, V.B., Bijalwan, V., Crespo, R.G. (eds) Proceedings of Integrated Intelligence Enable Networks and Computing. Algorithms for Intelligent Systems. Springer, Singapore. https://doi.org/10.1007/978-981-33-6307-6_58

Download citation

Publish with us

Policies and ethics