Principal Component Analysis as a Tool of Network Traffic Analysis for Detection of DDoS Attacks
摘要
To analyze network traffic based on the principal component method, a high-dimensional feature space was considered. Using the developed score space, cluster analysis and visualization of network connections were performed using observations of network traffic flows recorded during six different types of DDoS attacks, namely, DDoS Syn Flood, UDP Lag DDoS, UDP Flood DDoS, NetBIOS DDoS, LDAP DDoS, and MSSQL DDoS. The results of the study were validated through cross-checking. The principal component method is a powerful data intelligence analysis tool for supporting the monitoring and detection of suspicious events in cyberspace.