Data Mining Approach for Detection of DDoS Attacks Utilizing SSL/TLS Protocol

Image of a publication paper

Denial of Service attacks remain one of the most serious threats to the Internet nowadays. In this study, we propose an algorithm for detection of Denial of Service attacks that utilize SSL/TLS protocol. These protocols encrypt the data of network connections on the application layer which makes it impossible to detect attackers activity based on the analysis of packet payload. For this reason, we concentrate on statistics that can be extracted from packet headers. Based on these statistics, we build a model of normal user behavior by using several data mining algorithms. Once the model has been built, it is used to detect DoS attacks. The proposed framework is tested on the data obtained with the help of a realistic cyber environment that enables one to construct real attack vectors. The simulations show that the proposed method results in a higher accuracy rate when compared to other intrusion detection techniques.

Authors

Zolotukhin Mikhail, Hämäläinen Timo, Kokkonen Tero, Niemelä Antti, Siltanen Jarmo

Cite as

Zolotukhin M., Hämäläinen T., Kokkonen T., Niemelä A., Siltanen J. (2015) Data Mining Approach for Detection of DDoS Attacks Utilizing SSL/TLS Protocol. In: Balandin S., Andreev S., Koucheryavy Y. (eds) Internet of Things, Smart Spaces, and Next Generation Networks and Systems. ruSMART 2015, NEW2AN 2015. Lecture Notes in Computer Science, vol 9247. Springer, Cham

DOI

https://doi.org/10.1007/978-3-319-23126-6_25

Slide

Adding resilience to digital business

Slide

JYVSECTEC – Jyväskylä Security Technology is an independent research, development, and training center in Finland. We operate as part of Jamk University of Applied Science's Institute of Information Technology.

LinkedIn logo
YouTube logo
GitHub logo

Jamk University of Applied Sciences, Institute of Information Technology
Piippukatu 2, 40100 Jyväskylä, Finland
jyvsectec@jamk.fi

JYVSECTEC – Jyväskylä Security Technology © 2025 Finland.