Related Experiment Video
Updated: Mar 12, 2026

07:13
Early Detection of Cyanobacterial Blooms and Associated Cyanotoxins using Fast Detection Strategy
Published on: February 25, 2021
4.6K
A study on efficient detection of network-based IP spoofing DDoS and malware-infected Systems
1Graduate School of Information Security, Korea University, 145 Anam-ro, Seongbuk-gu, Seoul, Korea.
Springerplus
|November 12, 2016
Summary
This study introduces a novel method for real-time detection of distributed denial-of-service (DDoS) attacks, specifically those using IP-spoofed traffic from malware-infected systems. The developed algorithm effectively identifies these threats, enabling proactive intrusion responses to protect internal networks.
Area of Science:
- Computer Science
- Cybersecurity
- Network Security
Background:
- Large-scale networks face significant threats from distributed denial-of-service (DDoS) attacks, often amplified by malware-infected systems.
- IP-spoofed DDoS attacks pose a critical challenge, originating from compromised sources to disrupt internal network operations.
Purpose of the Study:
- To develop and evaluate an effective method for detecting IP-spoofed DDoS attacks and identifying malware-infected sources.
- To analyze the accuracy and performance of the proposed algorithm in real-time network traffic.
Main Methods:
- Calculating the frequency of network packet attributes and analyzing attribute anomalies.
- Proposing a novel algorithm for detecting IP-spoofed DDoS attacks and malware-infected systems.
- Developing a prototype to evaluate the algorithm's performance on real-time traffic.
Main Results:
- The proposed algorithm successfully detected internal network DDoS attacks in real-time.
- The system confirmed the presence of IP address spoofing during detected attacks.
- Malware-infected hosts triggering attacks were identified in real-time.
Conclusions:
- The developed method provides effective real-time detection of IP-spoofed DDoS attacks.
- Early detection of compromised systems enables timely intrusion responses, preventing network disruption.
- The algorithm demonstrates high accuracy and performance in identifying malicious network activities.