A New Network Flow Grouping Method for Defending Periodic Shrew DDoS Attacks in Cloud Computing

03 March 2016

New Image

Based on the investigation of periodic shrew distributed DoS Attacks among enormous normal end-users flow in cloud computing, this paper proposed to take frequency-domain characteristics from the autocorrelation sequence of network flow as clustering feature to group end-user flow data by BIRTH algorithm, and re-merge these clustering results into new groups by overcoming the deficiency of BIRTH algorithm. At last, the result of simulation proves the proposed method distinguishes abnormal network flows with higher detection accuracy and faster response time, and prevents abnormal network flow groups with less impaction.