| The DoS (Denial of Service) attack is one of the typical network attack methods,especially the new LDoS (Low-rate Denial of Service) attack. It is difficult to be detectedand defensed with a revolutionary new way to attack. Presently, the LDoS attackdetection methods are lack of accuracy, flexibility, real-time performance and resourcesconsumption. Therefore, it is of great significance to explore the new way to effectivelydetect the LDoS attack. This will help to increase the network security and preventnetwork crime.According to the TCP/IP (Transmission Control Protocol/Internet Protocol) con-gestion control strategy, the theory of the LDoS attack and its effects are described, andthe ACK (Acknowledgement) traffic characteristics are selected as the checking objects.Based on three different network scenarios, the distribution and fluctuationcharacteristics of ACK traffic are analyzed and compared through experiments. Theresults show the great differences in ACK traffic distribution and fluctuationcharacteristics between the LDoS-attacked scenario and other scenarios, and these twocharacteristics can be used to detect the LDoS attack.By checking ACK traffic distribution and fluctuation characteristics, the LDoS attackdetection methods are brought forward and the criterias are summarized. Mixing the twocharacteristics in one system, a prototype system is built to detect the LDoS attack.The effectiveness of the prototype system is verified using simulation, the resultsshow that the prototype system can get high detection efficiency and detection accuracywith a low false and missing positive rate. |