Application-level DDoS detection using service profiling

A method for detecting a malicious network activity. The method includes extracting, based on a pre-determined criterion, a plurality of protection phase feature sequences extracted from a first plurality of network traffic sessions exchanged during a protection phase between a server device and a f...

Full description

Saved in:
Bibliographic Details
Main Authors Modelo-Howard Gaspar, Kruegel Christopher, Vigna Giovanni, Lee Sung-Ju, Tongaonkar Alok, Zand Ali
Format Patent
LanguageEnglish
Published 13.12.2016
Subjects
Online AccessGet full text

Cover

Loading…
More Information
Summary:A method for detecting a malicious network activity. The method includes extracting, based on a pre-determined criterion, a plurality of protection phase feature sequences extracted from a first plurality of network traffic sessions exchanged during a protection phase between a server device and a first plurality of client devices of a network, comparing the plurality of protection phase feature sequences and a plurality of profiling phase feature sequences to generate a comparison result, where the plurality of profiling phase feature sequences were extracted from a second plurality of network traffic sessions exchanged during a profiling phase prior to the protection phase between the server device and a second plurality of client devices of the network, and generating, in response to detecting a statistical measure of the comparison result exceeding a pre-determined threshold, an alert indicating the malicious network activity.
Bibliography:Application Number: US201414550422