**Note on studying change point of LRD traffic based on Li’s detection of DDoS flood attacking.**
*(English)*
Zbl 1189.68024

Summary: Distributed denial-of-service (DDoS) flood attacks remain great threats to the Internet. To ensure network usability and reliability, accurate detection of these attacks is critical. Based on Li’s work on DDoS flood attack detection, we propose a DDoS detection method by monitoring the Hurst variation of long-range dependant traffic. Specifically, we use an autoregressive system to estimate the Hurst parameter of normal traffic. If the actual Hurst parameter varies significantly from the estimation, we assume that DDoS attack happens. Meanwhile, we propose two methods to determine the change point of Hurst parameter that indicates the occurrence of DDoS attacks. The detection rate associated with one method and false alarm rate for the other method are also derived. The test results on DARPA intrusion detection evaluation data show that the proposed approaches can achieve better detection performance than some well-known self-similarity-based detection methods.

### MSC:

68M11 | Internet topics |

68M10 | Network design and communication in computer systems |

94A13 | Detection theory in information and communication theory |

### Software:

longmemo
\textit{Z. Xia} et al., Math. Probl. Eng. 2010, Article ID 962435, 14 p. (2010; Zbl 1189.68024)

