BibTeX Entry


@inproceedings{LakhinaCrovellaDiot:flocon05,
  author	= {Lakhina, Anukool and Crovella, Mark and Diot, Christophe},
  title		= {Detecting Distributed Attacks using Network-Wide Flow Traffic},
  booktitle	= {Proceedings of FloCon 2005 Analysis Workshop},
  month		= sep,
  year		= {2005},
  location	= {New Orleans, LA},
  abstract	= {In this work, we present our methods to detect distributed attacks in backbone networks using sampled flow traffic data. Distributed attacks are traditionally viewed to be fundamentally more difficult to detect than single-source attacks. In contrast, we demonstrate that the more distributed an attack is, the better our methods are at detecting it. This is because our methods analyze correlations across all network-wide traffic simultaneously, instead of inspecting traffic on individual links in isolation. In addition, our methods are highly sensitive to the attack intensity; we show that attacks rates of less than 1\% of the underlying traffic can be detected successfully by our methods.},
  URL		= {http://www.cs.bu.edu/faculty/crovella/paper-archive/flocon05.pdf}
}