PFDetector: An Accurate and Low-Overhead Method for Detecting Periodic Flows in Network Traffic
Ieee AccessPeer ReviewedWenkai Mo +42026Magazines
Periodic flows are characterized by repeated appearances at regular time intervals in network traffic. These flows may conceal low-rate DoS attacks that gradually exhaust server resources while evading network traffic detection. Therefore, it is crucial to accurately detect periodic flows for network security. However, existing work on periodic-flow detection often struggles to achieve high detection accuracy, due to the resource constraints of its typically deployed devices such as switches. To resolve this issue, this paper proposes an accurate low-overhead detection method of periodic flows called PFDetector, which consists of two components: new-flow detector and periodic-flow identifier. The first component adopts a Bloom filter to rapidly detect first-appearing flows and skip repeated flows within each time window, significantly reducing computational and memory overhead of subsequent periodic-flow detection. The second component records potential periodic flows and tracks their periodicity for reporting real periodic flows. For the second component, we design a stable flow replacement strategy, which prioritizes flows with higher arrival frequencies and smaller inter-arrival time standard deviations under memory constraints. We further derive the false positive rate of the new-flow detector and the error bound of the periodic-flow identifier by theoretical analysis. Finally, we verify the performance of our proposed method PFDetector by experiments on real network traffic traces. Experimental results indicate that the PFDetector improves detection precision by approximately 4.5%, increases recall by approximately 8%, and reduces the average relative error by more than two times, compared to the state-of-the-art methods.
The content you want is available to Zendy users.
Already have an account? Sign inHaving issues? Contact support