Survey
* Your assessment is very important for improving the work of artificial intelligence, which forms the content of this project
* Your assessment is very important for improving the work of artificial intelligence, which forms the content of this project
Chapter 7
DETECTION OF DoS ATTACKS
IN THE KDD DATASET
For any anomaly detection system first and foremost thing is to be able to measure
its efficacy. With network anomaly detection schemes effective evaluation means that
the system should be able to detect the anomalies and be able to distinguish and
classify them accurately and timely.
However, these days, there are plenty of approaches that are being used to evaluate
the effectiveness of a system. But the biggest hurdle faced by most of them is the
paucity of datasets for testing and validation of their methodologies. Researchers
mainly depend on publicly available datasets for testing performance evaluation of
their algorithms and techniques. Till now one of the most favoured and widely used
dataset by the research community of intrusion detection is KDD’99 dataset (101).
In 1999, MIT Lincoln Labs developed training datasets devoted to the evaluation of
Intrusion Detection Systems (IDSs). The KDD’99 intrusion detection datasets are
sub-part of 1998 DARPA initiative (102), and simulated traces were generated in
a closed network environment. The whole simulation period lasted for seven weeks
and dataset consisted of normal connections as well as attack traffic. It is the only
available dataset with labeled normal and attack records and became a benchmark to
evaluate IDSs. Attacks captured in four categories were User to Root (U2R), Remote
to Local (R2L), Denial of Service (DoS) and Probe.
183
Although the KDD’99 dataset is considered as a benchmark in the IDSs community but there are a few who have raised the doubts about its authenticity. McHugh (124)
and Mahoney et. al. (125), in their works have pointed out that no validation was
ever performed on the dataset to show that the network traffic created in a closed environment was similar to real network traffic. With time the network dynamics have
also changed, and taking an old dataset for one’s performance evaluation raises its
own concerns. Nevertheless, we have used the KDD’99 dataset for the stated reasons:
1. It has been observed by William and Marin in their work published in (129)
that the DARPA data exhibits self-similarity within certain interval of time.
We choose KDD data set for our detection algorithm because KDD dataset is
derived from DARPA data set and is therefore expected to have self similarity
present in it. Our detection methodology is based on detection of anomalies
like DoS attacks in the network traffic. Since the KDD dataset is derived from
DARPA network traffic traces, we could use it for testing our methodology on
captured traffic traces in real network scenario.
2. It has been argued by Sabhnani and Serpen (126) that KDD data set cannot be
used for misuse-based IDS because of high variation in the attacks distribution
in training and testing data values. The coverage of new attacks, in the R2L
and U2R categories, in testing data is more than the known attacks. Therefore
no misuse-based IDS can show high accuracy in its detection rate. On the other
hand the accuracy of anomaly based detection algorithms is not badly affected
by the weaknesses of KDD dataset.
We therefore, in this chapter, have used set of DoS attacks in the KDD’99 dataset
to validate our detection methodology. Rest of the chapter covers in section 7.1 the
related work done by researchers in the area of DoS detection using KDD Dataset,
features of the dataset in section 7.2, proposed generic detection methodology in
section 7.3, details of the DoS attacks discussed in this chapter in section 7.4 followed
by results in section 7.5 and lastly summary of the chapter.
184
7.1
RELATED WORK
The KDD Dataset has been used in wide number of applications, namely, algorithms
based on entropy computations, fuzzy logic calculations, neural algorithms and various other statistical and signal processing techniques. In this section some of the
most relevant researches done on KDD dataset using anomaly detection techniques
in the recent years have been highlighted.
Tan et. al. in (127) have studied the techniques for detecting DoS attacks to
network services and have proposed an effective system for DoS attack detection
occurring on Internet Cloud. Their methodology for detecting known as well as unknown DoS attacks was based on learning the patterns of legitimate network traffic
and apply the idea of Multivariate Correlation Analysis (MCA) to network traffic
characterization and attack recognition. A triangle area technique has been used to
speed up the process of MCA. The influence of both non-normalized and normalized
data on the performance of the detection system has also been examined. The algorithm has been validated using KDD’99 dataset. The authors claim to outperform
the two state-of-the art approaches.
Liu et. al. in (182) have proposed Hurst parameter coupled by variance and autocorrelation as mechanism to spot the anomalous traffic in the computer network. The
proposed diagnosis mechanism was validated through experiments where the datasets
consisted of MIT Lincoln Laboratory DoS attack dataset and DDoS attack simulation experiments. Different from existing volume-based and feature-based methods,
researchers Du and Abe in (183) studied the DoS traffic characteristics from the view
point of the IP packet size distribution and have developed an IP packet size entropy
(IPSE)-based DoS detection scheme in which the presence of an attack was highlighted by drastic change in the entropy. The IPSE-based scheme was able to detect
long-term attacks as well as short-term attacks. The performance of the proposed
algorithm has been tested on experiments using real DARPA traffic-trace data sets.
Lee et. al. in (184) have presented an entropy-based network traffic profiling scheme
for the detection of DoS attacks. The proposed scheme firstly constructs a probability
185
distribution of Relative Uncertainty for normal network traffic behaviour and then
the Chi-Square Goodness-of-Fit Test has been used to detect DoS attacks. The probability distribution of the Relative Uncertainty for short-term network behaviour is
compared with that of the long-term profile constructed in the first stage. The algorithm has been tested with DoS attacks from KDD CUP 1999. Arajo et. al. in (185)
have worked on a method using approach toward an optimal subset of features for
selecting relevant features out of KDD99. Firstly, the information gain ratio for each
of the 41 features of KDD99 are computed, and then ranked according to their values. The calculated value was compared with the old value and the computation
stopped when no further improvements were possible. Cheng et. al. in (186) have
proposed DoS attacks detection method which used non parametric sequence test to
check the degree of estimation using high-order features. They have used two feature
selection algorithms, correlation based feature selection and fast correlation based
filter combined with symmetric uncertainty for detection. The algorithm calculated
informative features for distinguishing normal and anomalous DoS patterns. The algorithm has been tested on KDD dataset and yields results with improved accuracy.
Tritilanunt et. al. in (187) have used the detection algorithm based on Shannons
function for calculating entropy. They have applied the algorithm to input-output
traffic points in a network. The authors have been able to group together and analyze
packets with similar sizes for entropy computations. The works of Du and Abe (183)
have been referred to as well for selecting the duration of attacks. The experiments
have been tested with KDD Dataset and results are good for long term as well as
short term attacks. One of the strong feature of the algorithm is small detection time
in comparison to other entropy based detection techniques. Considering that DDoS
attacks destroy the distribution of traffic features in ISP domain and these variations
can be captured by entropic variations in stream samples the authors Sardana et.
al. (188) have proposed honeypot detection for attack traffic having statistically similar distribution features as legitimate traffic. They have proposed tolerance factor as
a calibration tool for finding out anomalous behaviour in the traffic by reducing false
alarms as well. The tests have been conducted on simulator NS-2 generated logs as
186
well Lincoln lab dataset and its subset KDD 99 dataset. The method gives detection
with minimum false positives and negatives. Gupta et. al. in (189) have also given
dynamic and auto responsive solution for DDoS attacks detection in ISP Networks.
Rawat and Sastry in (190) have also worked on wavelets based computation of self
similarity to detect DoS attacks in KDD Dataset. They employed Haar wavelet coefficients in order to calculate Hurst parameter for detecting and locating anomalies.
This was one of the few successful research works carried out on the original KDD
dataset using wavelets. Ghorbani et al. in (150) have worked in great detail and
analyzed the KDD Datset for all the four categories of the attacks using different
wavelets. It is a comprehensive comparison of four classic wavelet basis functions
Daubechies, Coiflets, Symlets and Discrete Meyer, for the purpose of network intrusion detection. They argue that a single type of wavelet is not sufficient to detect all
types of attacks present in the Dataset. Corrections to the dataset have also been
proposed by them.
The comparison of the above schemes that have used KDD Dataset is given in
Table 7.16. From the comparison we realized that our’s is the only scheme based on
detection of DoS attacks as network anomalies using hurst index as a single parameter
calculated on aggregated traffic series.
7.2
DoS ATTACKS IN THE KDD DATASET
Although the KDD CUP dataset (101) has many flaws as stated in (126), yet it is
the only dataset that is publicly available and is considered benchmark dataset for
testing of intrusion detection algorithms. It has labeled attack samples which are
obtained by passive monitoring, rather than by inserting the attack packets into the
normal traces. The datasets consist of two types of data: training and testing. Each
record of the training data is labeled as either normal or a specific kind of attack. The
training data contains a total of 22 attack types and an additional 15 attack types in
the test data only.
The attacks fall in one of the four categories which are Denial of Service (DoS),
187
Table 7.1: Basic features of individual TCP connections. Source: (101)
Dataset
Corrected KDD
10-percent Corrected KDD
Whole KDD
DoS
2,29,853
3,91,458
38,83,370
U2R
70
52
41,102
R2L
16,347
1,126
52
Probe
4,166
4,107
1126
Normal
60,593
97,278
9,72,780
Total
3,11,029
4,94,021
48,98,430
User to Root (U2R), Remote to local (R2L) and Probe.
1. Denial of Service(DoS): An attacker tries to prevent legitimate users from using
a service. For example, SYN flood, Smurf and teardrop.
2. User to Root (U2R): An attacker has local access to the victim machine and
tries to gain super-user privilege. For example, buffer overflow attacks.
3. Remote to Local (R2L): An attacker tries to gain access to victim machine
without having an account on it. For example, password guessing attack.
4. Probe: An attacker tries to gain information about the target host. For example,
port-scan and ping-sweep.
The numbers of samples of each category of attack in Corrected KDD and 10-percent
KDD training dataset are shown in Table 7.1. Being an elaborately labeled dataset,
it has a total of 41 attributes providing the specifics of the packets received. For this
experiment, the ‘Source Bytes Received’ attribute has been used. The scope of our
work is limited to detection of DoS attacks.
Each record of the dataset represents a connection between two network hosts according to existing network protocol and is described by 41 attributes (38 continuous
or discrete numerical attributes and 3 categorical attributes). This set of attributes includes general TCP features like duration, protocol type, service, src bytes, dst bytes,
flag, land, wrong fragment and urgent and derived features like the-same-host features
and the-same-service features.
These features are grouped into three sets: basic, content, and time-based traffic
features. The basic feature groups are shown in Table 7.2. A detailed description of
these features can be found in (92).
188
Since we have worked on DoS attacks only and therefore, give a brief background
about Smurf, Teardrop, Neptune, PoD, Back and LAND attacks for testing our detection algorithm:
1. Smurf: Smurf attacks in KDD dataset use ICMP echo request packets directed
to IP broadcast addresses from remote locations to create DoS attack. It can
be identified by watching large number of Echo requests and replies from the
victim machine. The coloumn ‘count’ values from the dataset can be read and
analysed for Smurf attacks. In our experimentation we have considered 280790
Smurf attacks in total.
2. Neptune: To initiate Neptune attack a large number of SYN packets are sent
to target machine to exhaust its buffer. Neptune attack never establishes the
TCP session resulting in many zero packets in each connection attempt. In our
experimentation we have considered 107201 Neptune attacks in altogether. As
a result of large number of SYN packets sent by the attacker nodes in case of
Neptune attack without actually establishing an actual session there is loss of
self similarity and the Hurst values go beyond the required limits. This happens
because of same size of incoming bytes for a long duration of time in the traffic.
No variation in hurst is used as a signal for attack.
3. Teardrop: Teardrop uses overlapping of IP fragments. It causes machines to
reboot. This attack affects systems that are still using old versions of Windows
Table 7.2: Attacks distribution in KDD Cup Training Dataset. Source: (101)
Feature Name
duration
protocol type
service
src bytes
dst bytes
flag
land
wrong fragment
Description
Length (number of seconds) of the connection
Type of the protocol
Network service on the destination
Number of data bytes from source to destination
Number of data bytes from destination to source
Normal or error status of the connection
1 if connection is from/to the same host/port;
0 otherwise
Number of ‘wrong’ fragments
189
Type
Continuous
Discrete
Discrete
Continuous
Continuous
Discrete
Discrete
Continuous
and Linux operating systems. In our experimentation we have considered 979
Teardrop attacks in total.
4. Ping-Of-Death (POD): POD affects older Operating Systems. It uses oversized IP packets to crash, freeze or reboot the system.During the experimentation POD affected none of the victim systems. ICMP packets longer than 64000
bytes can be due to POD attack. In our experimentation we have considered
264 POD attacks in total.
5. Back: In Back attacks the wrong IP addresses are used by the attacker in the
source IP address of the IP packet header. As a result the receiver fails to
determine the real attacking node. Since the attacker node cannot be located
therefore the attacker cannot be stopped from sending illegitimate packets. The
receiver thus gets inundated by unwanted packets and fails to provide service to
regular users thus causing denial of service. We have considered 2023 in total.
6. LAND (Local Area Network Denial): A LAND attack is a DoS attack
under which spoofed packets are sent to the target computer to bring it down.
In this attack large number of TCP/SYN packets are sent to the target machine.
These attacks are different from the SYN flooding attacks because in these
attacks the spoofed IP packets have both the source as well as the destination
IP addresses as the target machines IP address. The target machine therefore
keeps on sending reply to SYN packets to itself only and thus the buffer gets
filled up. The machine therefore fails to provide service to legitimate users.We
have considered 21 LAND attacks in total.
We next discuss our proposed generic detection methodology and the detection
results for DoS attacks in the KDD Dataset.
7.3
DETECTION METHODOLOGY
As already discussed in chapter 4, Figure 7-1 illustrates our proposed generic detection methodology. It has four phases out of which phase-II (Computation of Wavelet
190
Figure 7-1: Proposed Generic Detection Methodology MS-NAD
Coefficients), phase-III (Hurst Calculation & Threshold Testing) and phase-IV (Generate Visual MRO map) are important. We briefly rewrite them here to maintain
flow and interest of the reader.
In this chapter our task was to detect DoS attacks in the KDD Dataset using
self-similar nature of the network traffic and to see if the variation in the H index
could be used for distinguishing DoS attacks in the dataset from normal network
traffic. Though our proposed generic detection methodology has been explained in
detail in chapter 4, but to maintain the flow in reading we have briefly mentioned the
important points here as well:
1. The network traffic was captured & filtered in phase-I. The filtered traffic was
passed to phase-II, where wavelet decomposition of the signal was done to
generate the n-level coefficients. We needed to find out the scale-invariance
in measured network traffic at different scales. For this we used wavelets. Although there are other tools available but wavelets are best suited to measure the
scale-invariance property i.e. self-similarity because they themselves are scaleinvariant. Therefore, fast-pyramidal algorithm was used to measure multi-scale
decomposition coefficients. We have used daubechies-6 filter for our computations. We knew that for a given network traffic series the wavelet coefficients
define the multi-scale decomposition of energy. The major benefit of using
wavelet is that energy is an independent component at each level of decomposition. Therefore energy could be normalized at each scale independently. The
filtered signal was down-sampled by 2 at each level of the analysis procedure;
the signal of each level had an effect that sampling period extended 2 times. For
our study we have taken 10ms interval and therefore we decomposed to 13th
191
scale.
Mathematically, we could say that DWT represented a network signal X(t) =
P∞ P∞
j=0
k=−∞ d(j, k)φj,k (t) as a weighted sum of wavelets, where d(j, k) are the
wavelet coefficients at octave j and time k and φj,k (t) = 2−j/2 φ0 (2−j t − k), kZ,
is the wavelet obtained from an adequately chosen mother wavelet φ. The
wavelet φj,k is a scaled (by a factor of 2j ) and shifted (by k time units) version
of the mother wavelet.
2. Next step was to measure degree of self-similarity (phase-III), in the network traffic. We know that network traffic exhibits scale-invariance and hurst
parameter H is a measure of one of the scale invariance property i.e. selfsimilarity. Under normal circumstances the network traffic follows the self similar behaviour which can be measured with H. In the presence of anomalous
traffic their is deviation in the H value that could be measured and depending
upon the threshold it could be decided if an attack had occurred or not.
Mathematically, we know that the relationship between the variance of the
wavelet coefficients on a given octave and the octave j can be written as
E {d(j, k)2 } = 2jα cf C, where the average calculated for various k and C is
a constant dependent on the choice of the mother wavelet. E {d(j, k)2 } could
Pnj
therefore be computed as sample mean for all times as E {d(j, k)2 } = n1j k=1
|
dx (j, k) |2 , where nj is the number of wavelet coefficients available at octave
j. Linear relationship with a slope α(0 < α < 1) between log2 E {d(j, k)2 }
and j (called Logscale Plots) for a range of octaves, indicated presence of selfsimilarity. By performing linear regression of log2 E {d(j, k)2 } and j, H was
computed.
3. As a next step we had to generate the MRO maps (phase-IV), for visualization.
Using deviation in H value in phase-III, MS-NAD could find out if an attack had
happened or not but cannot find the Point-of-Presence (PoP). For that MRO
maps were plotted. There were 13 rows plotted as different scales or octaves
and each one of them was independent of the another. Because these levels
192
were independent of each other therefore MS-NAD could normalize the energy
values per row and could plot the normalized values. For better visualization
of the map MS-NAD assigned colors to these values. Matlab function imagesc
has been used to draw these maps. MS-NAD used a color scale from 1 to 64
with blue at 1 and red at 64 . For each value in the row vector a bar of color
depending upon the value in the vector was drawn. In our case we have hotter
color like red when the energy was high and cooler color like blue when normal
traffic was there.
Next section 7.4, we discuss the detection results of DoS attacks in the KDD
Dataset using logscale plots, H index and MRO maps.
7.4
DETECTION RESULTS OF DoS ATTACKS
IN KDD DATASET USING LOGSCALE PLOTS,
H INDEX AND MRO MAPS
Since the detection algorithm is a two step process in which we firstly compute Hurst
values and then find its point of presence therefore we look at variation in H to signal
possibility of an attack and then to find the point of occurrence we draw an Image of
the block of values in the given window.
The DoS attacks in the KDD Dataset were divided into two categories. First ones
consisted of long duration attacks like Smurf and Neptune. Second category consisted
of short duration attacks like PoD, Land and Teardrop. We state our observations
accordingly.
7.4.1
LOGSCALE PLOTS, H INDICES & MRO MAPS OF
LONG DURATION ATTACKS
In the experiment Daubechies-6 wavelet has been used to find out variations in self
similarity of the traffic. Block size is 8192 which is equivalent to 213 i.e. 13 scales.
193
Table 7.3: Start and end times of Smurf attacks wrt block numbers
Start Time
7794
43193
92155
128709
149858
370461
397013
487213
End Time
11488
50755
103649
136373
342984
371279
449785
490865
Starting Block No.
1
6
12
16
19
46
49
60
Ending Block No.
2
7
13
17
42
46
55
60
Attack Type
smurf.
smurf.
smurf.
smurf.
smurf.
smurf.
smurf.
smurf.
Based on the block size the attacks have been grouped as Long duration
attacks and Short duration attacks. Long duration are the ones that span
to more than one block of data. Both Smurf and Neptune come under
this category. We have observed that under normal conditions there is very small
variation in the H values but in the presence of these attacks there is considerable
change.
7.4.1.1
Detection Results of Smurf Attacks
In case of Smurf attacks the change in self-similarity was in the range of 0.1 to 0.3. In
general for both the attacks the change in self-similarity was followed by no change
at all for long intervals of time. We think that the reason for this was that there
was no change in the size of packets and hence the data size remained constant. And
because we measure variation in the traffic therefore absence of variation resulted in
out of range H values.
Secondly, absence of incoming traffic followed by Smurf attack packets gave H
values above threshold and therefore we looked out for second parameter i.e average packet size in order to decide the possible type of DoS attack. The parameter
source bytes i.e number of source bytes in the incoming data at the victim machine
has been used from the KDD Dataset to compute H values.
Important observations for Smurf attacks wrt logscale diagrams, H values, and
MRO maps were as follows:
1. In the data set Smurf attack instances were in blocks 1:2, 6:7, 12:13, 16:17,
194
(a) Block 1 MRO map
(b) Block 2 MRO map
(c) Block 12 MRO map
(d) Block 13 MRO map
(e) Block 19 MRO map
(f ) Block 20 MRO map
Figure 7-2: Multiresolution map of Smurf attacks
19:42, 46:46, 49:55 and 60:60. Table 7.3 shows start and stop times for Smurf
attacks. Table 7.4 shows H values for blocks 1:2, 6:7, 12:13, 16:17 and 19:20.
The constant value of H in some blocks was due to continuity of Smurf in more
than one block of data.
2. The hurst values decreased because of Smurf but did not fall below 0.5. This
meant that although the self similar nature of the traffic was disturbed due to
attack traffic but it did not lose it completely. This was due to constant size
data packets for long duration of time.
Table 7.4: Hurst Values Smurf Attacks in KDD Dataset
Block
Hurst
Block
Hurst
Block
Hurst
Nos.:
Value:
Nos.:
Value:
Nos.:
Value:
1
0.915
12
0.851
19
0.492
2
0.725
13
0.434
20
0.874
195
6
0.593
16
0.939
7
0.615
17
0.512
3. The incoming packets were of constant byte sizes of either 1032 bytes or 520
bytes. The start of the Smurf attack could be easily located in the MRO maps.
The average size of source bytes was either 1032 or 520 and therefore there was
presence of constant energy in the middle order scales. Long horizontal bars of
colors falling in the zone of normalized values of 40 to 64 in the scales 5 to 10
confirmed the presence of a Smurf attack.
4. Smurf attacks were long-duration attacks and therefore had impact in more
than one block of data. The occurence of Smurf attacks in the dataset is given
in the Table 7.3 wrt to block numbers. Figure 7-2 has subfigures (a) to (f) for
blocks 1, 2, 12, 13, 19 and 20 respectively. The start of the attack in Figure 7-2
(a) could be seen around time location 7794 which continued into the second
block Figure 7-2 (b) and died around time location 11488. Similarly, the start
of attack around time location 92155 and end of the attack around time location
103649 could be seen in Figures 7-2 (c) and (d), where due to the absence of
any other attack other than Smurf the distinctive horizontal bars of blue and
dark red can be seen in the mid-order scales. The dark red horizontal bars at
scales 1 to 3 in Figure 7-2 (f) for block 20 were due to constant data byte size
of incoming Smurf packets.
5. Logscale plots for blocks 1, 2, 3 and 4 are shown in Figure 7-3. From plots
it could be observed that the traffic in block 1 was highly bursty due to the
presence of normal traffic as well as attack traffic of Neptune and Smurf attacks.
This burstiness was diminished in block 2 and the drop in energy values at scale
7 could be mapped to mid-order Smurf attacks. For blocks 3 and 4 we received
almost horizontal lines which could be mapped to very low burstiness or loss of
burstiness.
6. The estimates for H thus obtained in Table 7.4 were consistent with those found
in these plots. From a wavelet decomposition perspective the results were true
as well because energy levels at different scales were independent of each other
and hence could be used to look out for low frequency attacks as well as high
196
Figure 7-3: Logscale Diagram of Blocks 1,2,3 and 4
frequency attacks.
7.4.1.2
Detection Results of Neptune Attacks
In case of Neptune the change in self similarity was in the range of 0.1 to 0.25. The
change in self similarity was followed by no change at all for long intervals of time.
We think that the reason for this was that there was no change in the size of packets
and hence the values remained constant.
Neptune was a long-duration attack like Smurf. Smurf was UDP based ICMP
packet attack whereas Neptune exploited the connection establishment (SYN flag)
Table 7.5: Start and end times of Neptune attacks wrt block numbers
Start Time
7602
53584
108134
140288
349383
372240
452340
459858
485185
486864
End Time
7603
74063
128693
140367
369927
396603
452419
480314
485797
486883
Starting Block No.
1
7
14
18
43
46
56
57
60
60
197
Ending Block No.
1
10
16
18
46
49
56
59
60
60
Attack Type
Neptune.
Neptune.
Neptune.
Neptune.
Neptune.
Neptune.
Neptune.
Neptune.
Neptune.
Neptune.
(a) Block 48 MRO map
(b) Block 49 MRO map
(c) Block 57 MRO map
(d) Block 58 MRO map
(e) Block 59 MRO map
(f ) Block 60 MRO map
Figure 7-4: Multiresolution map of Neptune attacks
of TCP protocol. Because Neptune sent SYN packets therefore size of bytes in IP
packet was zero i.e. no data was sent in Neptune attacks. Important observations
were as follows:
1. In the data set Neptune attack instances were in blocks 1:2, 7:10, 14:16, 18,
43:46, 46:49, 56, 57:59, and 60:60. Table 7.5 shows start and stop times for
Neptune attacks.
2. The H values for source bytes i.e incoming packet’s data size were computed
to detect Neptune attack. The H values fell sharply in the presence of Neptune
Table 7.6: Hurst Values Neptune Attacks in KDD Dataset
Block
Hurst
Block
Hurst
Block
Hurst
Nos.:
Value:
Nos.:
Value:
Nos.:
Value:
1
0.915
8
NaN
16
0.939
2
0.725
9
NaN
17
0.512
3
0.643
10
0.419
19
0.492
198
4
0.467
11
0.317
20
0.874
5
0.754
12
0.851
7
0.615
13
0.434
attack. Table 7.6 shows the H values for Neptune attacks. In some blocks
where Neptune attacks and Smurf attacks were common, for e.g. blocks 1 and
2, the H values showed high level of self-similarity.
3. Since Neptune packets had zero data therefore H values were NaN i.e. no value
present. We therefore had to rely on MRO maps for detection of Neptune
attacks.
4. In the MRO maps the attack was visible as small vertical bars with colors
ranging from blue to orange. The start of an attack was followed by images
of single ‘blue’ color as shown in Figures 7-4 (a) to (f). In blocks 48 and 49
Neptune attacks presence could be noticed by absence of no traffic and hence
blank MRO maps. In blocks 57 and 58 the Neptune attack started in the
beginning of block 57. The absence of traffic and hence no variation in color
bars in the block 57 and continuation till block 58 signaled presence of the
attack. Similar patterns could also be observed in blocks 59 and 60.
5. The KDD Dataset had few instances of Neptune attack where duration of the
attacks was not very long. These instances were of approximately 100ms duration and were not easily noticeable in the H values but the attacks could be
detected in the MRO maps as shown in figures.
7.4.2
LOGSCALE PLOTS, H INDICES & MRO MAPS OF
SHORT DURATION ATTACKS
PoD, Back, LAND and Teardrop were short-duration DoS attacks. The length of
these attacks was covered in one block only. We next state the observations of these
attacks.
7.4.2.1
Detection Results of POD Attacks
PoD was a short-duration attack with attack duration of 90 to 110ms. The important
observations in this case were as follows:
199
Table 7.7: Start and end times of PoD attacks wrt block numbers
Start Time
15785
82854
141614
142417
143273
344882
345952
369939
371379
456257
458738
End Time
15804
82873
141633
142418
143312
344921
345952
369958
371457
456276
458739
Starting Block No.
2
11
18
18
18
43
43
46
46
56
56
Ending Block No.
2
11
18
18
18
43
43
46
46
56
56
Attack Type
pod.
pod.
pod.
pod.
pod.
pod.
pod.
pod.
pod.
pod.
pod.
1. In the data set PoD attack instances were in blocks 2, 11, 18, 43, 46 and 56.
Table 7.7 shows start and stop times for PoD attacks. It could also be noted
from the Table 7.7 that PoD being small attacks, there multiple instance could
be observed in a single block.
2. For PoD attacks the segment size was considered to be 65,535 bytes and the
duration of these segments was 19 on average. The self similarity in the dataset
was in the range of 0.8 to 1. Whenever we had an attack like PoD the self
similarity dropped below 0.8 to the range of 0.7.
3. In case the number of PoD segments was more then the average of 19 in a single
block the self similarity dropped further to the range of 0.5. In case there were
more than one instances of PoD attacks in a single block then there was loss of
self similarity and the values fell below 0.5.
4. The H values for PoD attacks in blocks 43, 46 and 56 are shown in Table 7.8.
The fall in H values below 0.5 could be accounted to point stated above.
Table 7.8: Hurst Values PoD Attacks in KDD Dataset
Block Nos.:
Hurst Value:
43
0.337
200
46
0.361
56
0.361
5. As shown in Figure 7-5, PoD attacks could be spotted in the MRO map as thin
vertical lines. The small duration of the attack was visible in the map also.
(a) Block 2 MRO map
(b) Block 11 MRO map
(c) Block 18 MRO map
(d) Block 43 MRO map
(e) Block 46 MRO map
Figure 7-5: Multiresolution map of PoD attacks
6. The PoD attacks were similar to Smurf attacks but could be distinguished from
them due to their small duration and large data size in source bytes coloumn.
PoD attacks when appeared independently could be identified distinctively because of small pulse like lengths but in the presence of other attacks particularly
long-range Smurf attacks they could not be distinguished as shown in Figure
7-5e.
7. The Logscale Plots for PoD attacks were unable to show the presence of the
attack because of very small length of these attacks.
7.4.2.2
Detection Results of Teardrop Attacks
Teardrop was a short-duration attack with attack duration of 99 to 185 ms. The
201
Table 7.9: Start and end times of Teardrop attacks wrt block numbers
Start Time
19287
86545
141515
149209
346657
370060
370285
371280
490866
End Time
19385
86644
141613
149307
346755
370244
370383
371378
490965
Starting Block No.
3
11
18
19
43
46
46
46
60
Ending Block No.
3
11
18
19
43
46
46
46
60
Attack Type
teardrop.
teardrop.
teardrop.
teardrop.
teardrop.
teardrop.
teardrop.
teardrop.
teardrop.
difference between PoD attacks and Teardrop was that PoD was ICMP based attack
whereas Teardrop was UDP based attack. The data bytes were of size 28 bytes
whereas PoD was of 1480 bytes. The important observations in case of Teardrop
were as follows:
1. In the data set Teardrop attack instances were in blocks 3, 11, 18, 19, 43, 46
and 60. Table 7.7 shows start and stop times for PoD attacks. It could also
be noted from the Table 7.9 that Teardrop being small attacks, there multiple
instance could be observed in a single block, for e.g. block 46 had multiple
Teardrop instances.
2. It could also be noted from the H values in the Table 7.10 for Blocks 49 to 55
have long-duration highly self similar Smurf attack and we know that for Smurf
attacks the H values do not fall below 0.5 but because of the presence of teardrop
one can notice that the H values drop to 0.36 and therefore it can be stated that
although the pulses of Teardrop cannot be seen in the Multiresolution outlier
map but its presence can be felt from H values.
Table 7.10: Hurst Values Smurf & Teardrop Attacks in KDD Dataset
Block
Hurst
Block
Hurst
Block
Hurst
Nos.:
Value:
Nos.:
Value:
Nos.:
Value:
41
0.874
47
NaN
56
0.361
42
0.684
48
NaN
57
0.262
43
0.337
49
0.830
58
NaN
202
44
NaN
50
0.874
59
0.501
45
NaN
54
0.874
60
0.449
46
0.361
55
0.763
61
0.621
(a) Block 3 MRO map
(b) Block 11 MRO map
(c) Block 18 MRO map
(d) Block 43 MRO map
(e) Block 60 MRO map
Figure 7-6: Multiresolution map of Teardrop attacks
3. As shown in Figure 7-6, Teardrop attacks could be spotted in the MRO map
as thin vertical lines of ‘Blue’ color in the scales 1 to 9. The small duration of
the attack could also be noted from the length of bars in the map.
4. When Teardrop appeared independently it could be easily distinguished from
its blue bars as shown in sub-figures but in the company of long-range attacks
as Neptune it cannot be distinguished as shown in Figure 7-6b and 7-6e .
5. Teardrop was similar to Neptune attack for its small data bytes size of 28
and was different because it used UDP as its transport protocol than TCP for
Neptune. Although we had instances of short-duration Neptune but Neptune
attacks were largely long-duration attacks only.
6. The Logscale Plots for Teardrop attacks were unable to show the presence of
the attack because of very small length of these attacks.
203
Table 7.11: Start and end times of Back attacks wrt block numbers
Start Time
39724
50964
136554
480464
7.4.2.3
End Time
40723
51965
136654
480563
Starting Block No.
5
7
17
59
Ending Block No.
5
7
17
59
Attack Type
back.
back.
back.
back.
Detection Results of Back Attacks
Back is a short-duration DoS attack of either 1000ms or 100ms duration. It uses
HTTP/TCP as carriers of data. Back sends wrong IP addresses and large data
segments of sizes in five figures or more, e.g. 54540 bytes to inundate the victim.
The important observations were as follows:
1. In the data set Backs attack instances were in blocks 5, 7, 17, and 59. Table
7.11 shows start and stop times for Back attacks. Back attacks appeared independently so there independent impact could not be observed but important
observations were seen in the presence of Smurf as well as Neptune attacks.
2. The Back attacks affect the H values to a large extent because of large data
size. There was no block where these attacks appeared independently. For
Smurf the H values were further reduced from 0.87 to 0.5 and for Neptune the
H values were improved from NaN to 0.6/0.5. It can therefore be stated that
Back attacks keep the traffic self similar but introduce change in the H values.
Table 7.12 shows H values for blocks with Back attacks. The high degree of selfsimilarity could be observed from the high H values in these blocks. Although
these blocks had instances of other attacks as well but there combined impact
could not be ignored. The concrete evidence of Back attacks was however, done
with MRO maps only.
3. Sub-figures 7-7a and 7-7b are of Back attacks of duration 1000ms. As shown
in the figures it can be observed that Back attacks can be noticed in scales 3 to
Table 7.12: Hurst Values Back Attacks in KDD Dataset
Block Nos.:
Hurst Value:
5
0.806
7
0.852
204
17
0.663
58
NaN
59
0.619
(a) Block 5 MRO map
(b) Block 7 MRO map
(c) Block 17 MRO map
(d) Block 59 MRO map
Figure 7-7: Multiresolution map of Back attacks
8 as horizontal bars of colors ‘blue’ as well as hotter colors ‘orange,red’. These
bars are similar to long bars of Smurf attacks but their color intensity is high.
It was due to very large data size in bytes.
4. Back Attacks of duration 100ms in sub-figures 7-7c and 7-7d can also be
distinguished in the scales 3 to 8. The mellower range of colors and smaller
length of bars is due to smaller time span of these attacks in this case.
5. The Logscale Plots for Back attacks were unable to show the presence of the
attack because of very small length of these attacks.
7.4.2.4
Detection Results of LAND Attacks
LAND is local area network denial attack of 1.75ms duration on average. It uses TCP
as transport protocol. LAND is a localized Local Area Network attack and uses ‘finger
user information protocol’ to bring down the victim computer. The attack packets
205
Table 7.13: Start and end times of LAND attacks wrt block numbers
Start Time
31690
76103
76193
76325
76490
78173
78243
78391
78532
349382
455981
485183
End Time
31690
76103
76193
76325
76494
78173
78243
78391
78536
349382
455981
485184
Starting Block No.
4
10
10
10
10
10
10
10
10
43
56
60
Ending Block No.
4
10
10
10
10
10
10
10
10
43
56
60
Attack Type
land.
land.
land.
land.
land.
land.
land.
land.
land.
land.
land.
land.
do not carry any data bytes in the source bytes coloumn as well as destination bytes
of the KDD Dataset. Important observations for LAND attacks were:
1. In the data set LAND attack instances were in blocks 4, 10, 43, 56 and 60. Table
7.13 shows start and stop times for LAND attacks. It could also be noted from
the Table 7.13 that LAND being small attacks, there multiple instance could
be observed in a single block, for e.g. block 10 had multiple LAND instances.
2. LAND is a very small duration attack. Detection of such a small attack in the
block size of 8192ms is very difficult. As shown in the Figure 7-8 detection
of the attack in combination with other attacks is possible but independent
detection is not possible.
(a) Block 4 MRO map
(b) Block 10 MRO map
(c) Block 43 MRO map
Figure 7-8: Multiresolution map of LAND attacks
206
3. Since independent detection of LAND is not possible therefore another parameter value of coloumn seven i.e. land has been used. It is 1 if the connection is
from same host to same port and 0 otherwise. This value is 1 for LAND attacks
and can therefore be used to detect LAND attacks.
4. The Logscale Plots for LAND attacks were unable to show the presence of the
attack because of very small length of these attacks.
7.4.3
COMPUTATION OF CONFUSION MATRIX
The confusion matrix is a ranking method. The size of the confusion matrix is dependent on the number of individual types that are to be detected. In confusion matrix
the actual type instances are compared with predicted type instances of a dataset.
Correct classification is shown on the diagonal. The confusion matrix for anomaly
detection system is a 2-by-2 matrix. The true negatives and true positives represent
the accurate predictions and therefore lie on the matrix diagonal whereas the false
negatives and false positives lie on the right and left sides of the diagonal respectively.
Accuracy is a metric that is used to see how accurately the detection algorithm works.
It measures the percentage of true detection and true failures that are generated by
the algorithm. When a detection algorithm declares a data to be an anomaly or not
then it can be either right or wrong. It assumes true for right and false for wrong,
respectively.
Lets consider a detector D and Dt a set of test instances. If an instance that is an
attack p is predicted as an attack Y by the detector D, it is called true positive TP;
but if it is predicted as normal N then it is counted as false negative FN. Similarly,
if an instance is normal n and is predicted as normal N then it is known as true
negative TN, but if it is predicted as an attack Y then it is a false positive FP. The
true positive rate TPR is therefore percentage of attack instances detected accurately
to the total number of attack instances present in the dataset. TPR is also known as
sensitivity. The false positive rate FPR is the percentage of normal traffic instances
that are wrongly declared as an attack to the total number of normal traffic instances
207
Predicted Values
Smurf
Neptune
Teardrop
PoD
Back
LAND
Normal
Smurf
280590
0
0
0
0
0
200
Neptune
0
107199
0
0
0
0
2
True Values
Teardrop PoD
0
99
100
3
879
0
0
162
0
0
0
0
0
0
Back
0
0
0
0
2203
0
0
LAND
0
0
0
0
0
21
0
Normal
0
843
0
0
0
1
96433
Table 7.14: Confusion Matrix
in the dataset. It is also called specificity. All the four, TPR, FPR, TNR and FNR are
defined for a normal class. The performances of each method are measured according
to the Accuracy, True Positive Rate (TP), True Negative Rate (TN), False Positive
Rate (FP) and False Negative Rate (FN).
Table 7.15: Test results of detection algorithm
Accuracy
TP Rate
TN Rate
FP Rate
FN Rate
99.79%
99.95%
99.13%
0.87%
0.05%
Table 7.14 lists the true values and predicted values for the six DoS attacks,
namely, Smurf, Neptune, Teardrop, PoD, Back and LAND attacks, in the KDD
Dataset. The 10% KDD Dataset has a total of 280790 Smurf, 107201 Neptune, 979
Teardrop, 264 PoD, 2203 Back, 21 LAND and 97277 instances of normal traffic.
From the Table 7.14 it can be seen that out of these 200 Smurf attack instances
and 2 instances of Neptune were wrongly considered as normal traffic instances.100
Teardrop instances were wrongly identified as Neptune attacks, 102 PoD instances
were detected as Smurf attacks and Neptune attacks and 843 normal instances were
detected as Neptune attacks. Overall statistics are given in the Table 7.15. Our
detection methodology was therefore able to successfully detect 99.79% DoS attacks.
The comparison of our proposed detection methodology with other
schemes that have also used KDD Dataset is given in Table 7.16.
208
Table 7.16: Comparison of Different Techniques with respect to KDD Dataset
Authors[YOP]
W. Lu et.
al.
[2009]
S. Rajasegarar et.
al., [2010]
Technique
Wavelets based detection
multiclass conic segmentation SVM
P
15
Lu et. al. [2010]
41
99.97 %
7
94.04 %
al.
conditional
random
fields
Weighted
Ensemble
model
growing hierarchical self
organizing map , pattern analysis
Wavelets based
6
33 %
et.
LBG algorithm
10
98.75 %
et.
AODE algorithm
NM 99.7 %
learning based
al.
KPC Analysis
PSO, SVM
NM 96.5 %
results vary depending upon
weights assigned, high dimension
space
only works for TCP and UDP
packets
learning based
J. Yan et.
al.
[2010]
D. Ippoliti et. al.
[2010]
L. F. Lu et.
[2010]
X.
Wang
al.[2011]
Z. A. Baig
al.[2011]
X. Xu et.
[2011]
R. Vijayasarathy
et. al. [2011]
R. Karbaschian
et. al.[2012]
Ali et. al.[2012]
C. Callegari, et.
al [2012]
R. P. Palnaty et.
al.[2013]
S. Novakov et. al.
[2013]
A. Aborujilah et.
al. [2013]
Z. Tan et.
al
[2014]
and
Naive Bayesian classifier
Similarity based alert
correlation
Resilience Strategy, coclustering algorithms
Jaccard Similarity Coefficient
PCA, clustering and
Wavelet-based spectral
analysis
remove correlated attributes algorithm
multivariate correlation
analysis
Results
all attacks
NM 99.2 %
NM 75.84
99.79 %
-
7
98.3 - 99.5
%
NM 98.0484 %
15
79.4231 %
4
80-88 %
39
67 %
14
71-77 %
NM 84 - 99.47 %
32
95.20 %
Weakness
Large number of parameters with
no fixed wavelet
Training required, normalization
required, only SYN flood, land
attack
Requires prior testing for deciding dynamic weights
Requires prior training, works
well for large samples of data
depending upon number of clusters Requires normalization and
offline training
Requires normalization of data
large number of input parameters
Depends heavily on protocol and
services attributes
PCA and Haar wavelet methods
failed to pick all the infected bins
Training required, only for flooding based DDoS
does not work well in identifying
Land, Neptune, and Teardrop attack records
Proposed Tech- Self-Similarity
based 1
99.79 %
nique
detection of anomalies
YOP-Year of Publication; P-Number of Parameters; NM-Not Mentioned
209
7.5
SUMMARY
In this chapter we tested our wavelets based estimation of Hurst values for selfsimilarity so as to detect changes and henceforth trace an attack in the network
traffic. The overall accuracy of the proposed model is 99.79% with true positive
rate of 99.95%, true negative rate of 99.13%, false positive rate of 0.87% and false
negative rate of 0.05%. We therefore can conclude that variation in self similar nature
of the network traffic can be considered for detection of DoS attacks particularly longduration attacks.
210