• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

Computer Engineering & Science

Previous Articles     Next Articles

A DDoS attack security situation assessment model
based on improved fuzzy C-means clustering

  

  1. (1.School of Information Science and Technology,Hainan University,Haikou 570228;
    2.State Key Laboratory of Marine Resource Utilization in South China Sea,Haikou 570228,China)
  • Received:2018-06-20 Revised:2018-08-19 Online:2018-11-25 Published:2018-11-25

Abstract:

Traditional network situation assessment methods cannot effectively evaluate the distributed denial of service (DDoS) attack security situation in the new network environment. We propose a DDoS attack security situation assessment model based on improved fuzzy C-means (FCM) clustering. This model generates a fusion feature gained from network flow IP address changes of old and new users and unilateral and bilateral network flow, and calculates the risk indexes of each network node on the basis of the fusion feature. The security situation information of the whole network can be obtained by fusing the risk indexes of all the nodes in the network, which is then classified into five security levels by the improved FCM. The DDoS attack security situation of the whole network therefore can be quantitatively evaluated by the proposed model. Experiments on real DDoS data show that the proposed model can assess the DDoS attack security situation reasonably and effectively, and it is more flexible and accurate than existing methods.
 

Key words: distributed denial of service(DDoS), security situation assessment, fuzzy C-means(FCM), risk assessment