Detecting denial of service attacks using emergent self-organizing maps

Aikaterini Mitrokotsa (Institutionen för data- och informationsteknik (Chalmers)) ; Christos Douligeris
5th IEEE International Symposium on Signal Processing & Information Technology p. 375 - 380. (2005)
Denial of service attacks constitute one of the greatest problem in network security. Monitoring traffic is one of the main techniques used in order to find out the existence of possible outliers in the traffic patterns. In this paper, we propose an approach that detects denial of service attacks using emergent self-organizing maps. The approach is based on classifying "normal" traffic against "abnormal" traffic in the sense of denial of service attacks. The approach permits the automatic classification of events that are contained in logs and visualization of network traffic. Extensive simulations show the effectiveness of this approach compared to previously proposed approaches regarding false alarms and detection probabilities

Nyckelord: Denial of Service attacks, self-organising maps, classification

