分析了针对DNS服务器DDoS攻击的特征,提出了一种基于攻击流特征(AFC)时间序列的DDoS攻击检测方法.通过自适应自回归模型的参数拟合,将AFC时间序列变换为多维空间内的自适应自回归AAR模型参数向量序列,然后使用支持向量机进行分类.实验结果表明,该方法能有效检测针对DNS服务器的DDoS攻击.
Through the analysis of distributed denial of service (DDoS) attack towards the DNS server, a novel method to detect DDoS attack is proposed based on the AFc time series, which is defined by attack flow characteristics. By approximating the adaptive autoregTessi'~e model, the AFC time series are trans- formed into a multidimensional vector series. Furthermore, a support vector machine classifier is applied to identity the attacks. The experiment results show that this method can detect DDoS attacks effectively.