TVis: A Light-weight Traffic Visualization System for DDoS Detection | IEEE Conference Publication | IEEE Xplore

TVis: A Light-weight Traffic Visualization System for DDoS Detection


Abstract:

With rapid growth of network size and complexity, network defenders are facing more challenges in protecting networked computers and other devices from acute attacks. Tra...Show More
Notes: This article was mistakenly omitted from the original submission to IEEE Xplore. It is now included as part of the conference record.

Abstract:

With rapid growth of network size and complexity, network defenders are facing more challenges in protecting networked computers and other devices from acute attacks. Traffic visualization is an essential element in an anomaly detection system for visual observations and detection of distributed DoS attacks. This paper presents an interactive visualization system called TVis, proposed to detect both low-rate and highrate DDoS attacks using Heron’s triangle-area mapping. TVis allows network defenders to identify and investigate anomalies in internal and external network traffic at both online and offline modes. We model the network traffic as an undirected graph and compute triangle-area map based on incidences at each vertex for each 5 seconds time window. The system triggers an alarm iff the system finds an area of the mapped triangle beyond the dynamic threshold. TVis performs well for both low-rate and high-rate DDoS detection in comparison to its competitors.
Notes: This article was mistakenly omitted from the original submission to IEEE Xplore. It is now included as part of the conference record.
Date of Conference: 30 October 2019 - 01 November 2019
Date Added to IEEE Xplore: 16 April 2020
ISBN Information:
Conference Location: Chiang Mai, Thailand