1. Minimal Triangle Area Mahalanobis Distance for Stream Homogeneous Group-based DDoS Classification.
- Author
-
Purwanto, Yudha, Kuspriyanto, Hendrawan, and Rahardjo, Budi
- Subjects
DENIAL of service attacks ,INTRUSION detection systems (Computer security) ,HOMOGENEOUS catalysis ,DATA analysis ,DECISION trees - Abstract
An Intrusion Detection System (IDS) which implement a group-based classification algorithm, theoretically has the benefit of higher accuracy. Unfortunately, higher accuracy only achieved if the observed group is homogeneous from a certain distribution. Recently, a distributed denial of service (DDoS) attack consists of multiple botnets which produce multi types of traffic in one attack session. It makes the IDS suffers from decreasing accuracy as the increasing heterogeneity within the observed group. To address the problem, we propose homogeneous grouping algorithm based on triangle area Mahalanobis distance to support IDS which implement group-based data analysis. First, the Mahalanobis distance measurement was used to construct homogeneous groups. Then, the covariance matrix of each homogeneous group was classified using a decision tree classifier. Classification performance was evaluated using known KDDCup 99 dataset. The results pointed out that the used of homogeneous grouping algorithm improve the classification performance for natural and mixed random DDoS traffic. [ABSTRACT FROM AUTHOR]
- Published
- 2018
- Full Text
- View/download PDF