@article { author = {Nooribakhsh, Mahsa and Mollamotalebi, Mahdi}, title = {F-STONE: A Fast Real-Time DDOS Attack Detection Method Using an Improved Historical Memory Management}, journal = {The ISC International Journal of Information Security}, volume = {12}, number = {2}, pages = {113-128}, year = {2020}, publisher = {Iranian Society of Cryptology}, issn = {2008-2045}, eissn = {2008-3076}, doi = {10.22042/isecure.2020.167450.453}, abstract = {Distributed Denial of Service (DDoS) is a common attack in recent years that can deplete the bandwidth of victim nodes by flooding packets. Based on the type and quantity of traffic used for the attack and the exploited vulnerability of the target, DDoS attacks are grouped into three categories as Volumetric attacks, Protocol attacks and Application attacks. The volumetric attack, which the proposed method attempts to detect it, is the most common type of DDoS attacks. The aim of this paper is to reduce the delay of real-time detection of DDoS attacks utilizing hybrid structures based on data stream algorithms. The proposed data structure (BHM ) improves the data storing mechanism presented in STONE method and consequently reduces the detection time. STONE characterizes regular network traffic of a service by aggregating it into common prefixes of IP addresses, and detecting attacks when the aggregated traffic deviates from the regular one. In BHM, history refers to the output traffic information obtained from each monitoring period to form a reference profile. The reference profile is created by employing historical information and only includes normal traffic information. The delay of DDoS attack detection increases in STONE due to long-time intervals between each monitoring period. The proposed method (F-STONE) has been compared to STONE based on attack detection time, Expected Profile Update Time (EPUT), and rate of attack detection. The evaluation results indicated significant improvements in terms of the EPUT, acceleration of attack detection and reduction of false positive rate.}, keywords = {DDoS detection,Real time detection,Data stream algorithm,Binary-mapped Historical-memory Management,Anomaly Detection,Expected Profile Update Time}, url = {https://www.isecure-journal.com/article_107959.html}, eprint = {https://www.isecure-journal.com/article_107959_bf49f140f7f9e82841dd4f64c81f6a5e.pdf} }