RUS  ENG
Full version
JOURNALS // Izvestiya of Saratov University. Mathematics. Mechanics. Informatics // Archive

Izv. Saratov Univ. Math. Mech. Inform., 2024 Volume 24, Issue 3, Pages 452–462 (Mi isu1043)

Scientific Part
Computer Sciences

Detection of sources of network attacks based on the data sampling

E. S. Sagatov, A. M. Sukhov, V. V. Azmyakov

Sevastopol State University, 33 Universitetskaya St., Sevastopol 299053, Russia

Abstract: This article defines the rules for finding the threshold values for the main network variables used to detect network intrusions under conditions of limited data sampling. The sFlow technology operates with a limited sample of packets, and one packet out of 50 can be analyzed, but this value can reach 5000. The main conclusion is that the product of the threshold value and sample resolution remains a constant value. The article defines the size of the maximum resolution, at which an attack with a given threshold can be detected. Based on the experimental data, this hypothesis was tested; considering the experimental error, it was verified.

Key words: thresholds for detecting DDoS attacks, sFlow data sampling, rank distributions in network security.

UDC: 004.7

Received: 21.03.2023
Accepted: 29.05.2023

Language: English

DOI: 10.18500/1816-9791-2024-24-3-452-462



© Steklov Math. Inst. of RAS, 2025