{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,19]],"date-time":"2026-06-19T17:28:23Z","timestamp":1781890103325,"version":"3.54.5"},"reference-count":40,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2020,2,6]],"date-time":"2020-02-06T00:00:00Z","timestamp":1580947200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2020,2,6]],"date-time":"2020-02-06T00:00:00Z","timestamp":1580947200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"crossref","award":["61772189"],"award-info":[{"award-number":["61772189"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/501100004735","name":"Hunan Provincial Natural Science Foundation of China","doi-asserted-by":"crossref","award":["2019JJ40037"],"award-info":[{"award-number":["2019JJ40037"]}],"id":[{"id":"10.13039\/501100004735","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Hum. Cent. Comput. Inf. Sci."],"published-print":{"date-parts":[[2020,12]]},"abstract":"<jats:title>Abstract<\/jats:title>\n               <jats:p>Low-rate denial of service (LDoS) attacks send attacking bursts intermittently to the network which can severely degrade the victim system\u2019s Quality of Service (QoS). The low-rate nature of such attacks complicates attack detection. LDoS attacks repeatedly trigger the congestion control mechanism, which can make TCP traffic extremely unstable. This paper investigates the network traffic\u2019 characteristics, in which variance and entropy are used to evaluate the TCP traffic\u2019s characteristics, and the ratio of UDP traffic to TCP traffic (UTR) is also analyzed. Thus, a detection method combining two-step cluster analysis and UTR analysis is proposed. Through two-step cluster analysis which is one of the machine learning algorithms, network traffic is divided into multiple clusters and then clusters subjected to LDoS attacks are determined using UTR analysis. NS2 simulation platform and test-bed network environment aim to evaluate the detection approach\u2019s performance. To better assess the effectiveness of the method, public dataset WIDE is also utilized. Experimental results with a good performance prove that the proposed detection approach can accurately detect LDoS attacks.<\/jats:p>","DOI":"10.1186\/s13673-020-0210-9","type":"journal-article","created":{"date-parts":[[2020,3,6]],"date-time":"2020-03-06T13:19:16Z","timestamp":1583500756000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":23,"title":["Low-rate DoS attack detection based on two-step cluster analysis and UTR analysis"],"prefix":"10.1186","volume":"10","author":[{"given":"Dan","family":"Tang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Rui","family":"Dai","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Liu","family":"Tang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xiong","family":"Li","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2020,2,6]]},"reference":[{"key":"210_CR1","doi-asserted-by":"publisher","first-page":"284","DOI":"10.1016\/j.cose.2019.01.002","volume":"82","author":"J David","year":"2019","unstructured":"David J, Thomas C (2019) Efficient ddos flood attack detection using dynamic thresholding on flow-based network traffic. Comput Secur 82:284\u2013295","journal-title":"Comput Secur"},{"key":"210_CR2","doi-asserted-by":"crossref","unstructured":"Aiello M, Cambiaso E, Scaglione S, Papaleo G (2013) A similarity based approach for application dos attacks detection. In: 2013 IEEE symposium on computers and communications (ISCC), IEEE, pp 000430\u2013000435","DOI":"10.1109\/ISCC.2013.6754984"},{"key":"210_CR3","doi-asserted-by":"crossref","unstructured":"Hodo E, Bellekens X, Hamilton A, Dubouilh P-L, Iorkyase E, Tachtatzis C, Atkinson R (2016) Threat analysis of iot networks using artificial neural network intrusion detection system. In: 2016 international symposium on networks, computers and communications (ISNCC), IEEE, pp 1\u20136","DOI":"10.1109\/ISNCC.2016.7746067"},{"key":"210_CR4","doi-asserted-by":"publisher","first-page":"198","DOI":"10.1016\/j.future.2019.08.007","volume":"102","author":"ZA Baig","year":"2020","unstructured":"Baig ZA, Sanguanpong S, Firdous SN, Nguyen TG, So-In C et al (2020) Averaged dependence estimators for dos attack detection in iot networks. Future Gener Comput Syst 102:198\u2013209","journal-title":"Future Gener Comput Syst"},{"key":"210_CR5","doi-asserted-by":"crossref","unstructured":"Dridi L, Zhani MF (2016) Sdn-guard: Dos attacks mitigation in sdn networks. In: 2016 5th IEEE international conference on cloud networking (Cloudnet), IEEE, pp 212\u2013217","DOI":"10.1109\/CloudNet.2016.9"},{"issue":"1","key":"210_CR6","doi-asserted-by":"publisher","first-page":"16","DOI":"10.1186\/s13673-019-0176-7","volume":"9","author":"M Imran","year":"2019","unstructured":"Imran M, Durad MH, Khan FA, Derhab A (2019) Reducing the effects of dos attacks in software defined networks using parallel flow installation. Hum Cent Comput Inf Sci 9(1):16","journal-title":"Hum Cent Comput Inf Sci"},{"issue":"16","key":"210_CR7","doi-asserted-by":"publisher","first-page":"3724","DOI":"10.1002\/sec.1539","volume":"9","author":"M Masdari","year":"2016","unstructured":"Masdari M, Jalali M (2016) A survey and taxonomy of dos attacks in cloud computing. Secur Commun Netw 9(16):3724\u20133751","journal-title":"Secur Commun Netw"},{"issue":"12","key":"210_CR8","doi-asserted-by":"publisher","first-page":"3655","DOI":"10.1007\/s00521-016-2317-5","volume":"28","author":"B Gupta","year":"2017","unstructured":"Gupta B, Badve OP (2017) Taxonomy of dos and ddos attacks and desirable defense mechanism in a cloud computing environment. Neural Comput Appl 28(12):3655\u20133682","journal-title":"Neural Comput Appl"},{"issue":"1","key":"210_CR9","doi-asserted-by":"publisher","first-page":"383","DOI":"10.1109\/TCNS.2016.2614099","volume":"5","author":"H Zhang","year":"2016","unstructured":"Zhang H, Qi Y, Wu J, Fu L, He L (2016) Dos attack energy management against remote state estimation. IEEE Trans Control Netw Syst 5(1):383\u2013394","journal-title":"IEEE Trans Control Netw Syst"},{"issue":"7","key":"210_CR10","doi-asserted-by":"publisher","first-page":"1069","DOI":"10.1109\/TIFS.2014.2321034","volume":"9","author":"J Luo","year":"2014","unstructured":"Luo J, Yang X, Wang J, Xu J, Sun J, Long K (2014) On a mathematical model for low-rate shrew ddos. IEEE Trans Inf Forensics Secur 9(7):1069\u20131083","journal-title":"IEEE Trans Inf Forensics Secur"},{"issue":"3\u20134","key":"210_CR11","doi-asserted-by":"publisher","first-page":"300","DOI":"10.1504\/IJTMCC.2013.056440","volume":"1","author":"E Cambiaso","year":"2013","unstructured":"Cambiaso E, Papaleo G, Chiola G, Aiello M (2013) Slow dos attacks: definition and categorisation. Int J Trust Manage Comput Commun 1(3\u20134):300\u2013319","journal-title":"Int J Trust Manage Comput Commun"},{"key":"210_CR12","doi-asserted-by":"crossref","unstructured":"Mongelli M, Aiello M, Cambiaso E, Papaleo G (2015) Detection of dos attacks through fourier transform and mutual information. In: 2015 IEEE international conference on communications (ICC), IEEE, pp 7204\u20137209","DOI":"10.1109\/ICC.2015.7249476"},{"key":"210_CR13","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2019.2948167","author":"M Yue","year":"2019","unstructured":"Yue M, Wang M, Wu Z (2019) Low-high burst: a double potency varying-rtt based full-buffer shrew attack model. IEEE Trans Dependable Secure Comput. https:\/\/doi.org\/10.1109\/TDSC.2019.2948167","journal-title":"IEEE Trans Dependable Secure Comput"},{"issue":"15","key":"210_CR14","doi-asserted-by":"publisher","first-page":"2711","DOI":"10.1016\/j.comnet.2010.05.002","volume":"54","author":"G Maci\u00e1-Fern\u00e1ndez","year":"2010","unstructured":"Maci\u00e1-Fern\u00e1ndez G, Rodr\u00edguez-G\u00f3mez RA, D\u00edaz-Verdejo JE (2010) Defense techniques for low-rate dos attacks against application servers. Comput Netw 54(15):2711\u20132727","journal-title":"Comput Netw"},{"key":"210_CR15","doi-asserted-by":"crossref","unstructured":"Cambiaso E, Papaleo G, Chiola G, Aiello M (2015) Designing and modeling the slow next dos attack. In: Computational intelligence in security for information systems conference, Springer, pp 249\u2013259","DOI":"10.1007\/978-3-319-19713-5_22"},{"key":"210_CR16","first-page":"23","volume":"35","author":"E Cambiaso","year":"2017","unstructured":"Cambiaso E, Papaleo G, Aiello M (2017) Slowcomm: design, development and performance evaluation of a new slow dos attack. J Inf Secur Appl 35:23\u201331","journal-title":"J Inf Secur Appl"},{"issue":"5","key":"210_CR17","doi-asserted-by":"publisher","first-page":"414","DOI":"10.1109\/LCOMM.2006.1633341","volume":"10","author":"T Cui","year":"2006","unstructured":"Cui T, Andrew LL, Zukerman M, Tan L (2006) Improving the fairness of fast tcp to new flows. IEEE Commun Lett 10(5):414\u2013416","journal-title":"IEEE Commun Lett"},{"key":"210_CR18","doi-asserted-by":"publisher","first-page":"80","DOI":"10.1016\/j.comnet.2018.02.029","volume":"136","author":"Z Chen","year":"2018","unstructured":"Chen Z, Yeo CK, Lee BS, Lau CT (2018) Power spectrum entropy based detection and mitigation of low-rate dos attacks. Comput Netw 136:80\u201394","journal-title":"Comput Netw"},{"issue":"5","key":"210_CR19","doi-asserted-by":"publisher","first-page":"559","DOI":"10.1109\/TDSC.2015.2443807","volume":"13","author":"Z Wu","year":"2015","unstructured":"Wu Z, Zhang L, Yue M (2015) Low-rate dos attacks detection based on network multifractal. IEEE Trans Dependable Secure Comput 13(5):559\u2013567","journal-title":"IEEE Trans Dependable Secure Comput"},{"issue":"1","key":"210_CR20","doi-asserted-by":"publisher","first-page":"189","DOI":"10.3390\/s20010189","volume":"20","author":"S Zhan","year":"2020","unstructured":"Zhan S, Tang D, Man J, Dai R, Wang X (2020) Low-rate dos attacks detection based on maf-adm. Sensors 20(1):189","journal-title":"Sensors"},{"key":"210_CR21","doi-asserted-by":"crossref","unstructured":"Tang D, Dai R, Tang L, Zhan S, Man J (2018) Low-rate dos attack detection based on two-step cluster analysis. In: International conference on information and communications security, Springer, pp 92\u2013104","DOI":"10.1007\/978-3-030-01950-1_6"},{"key":"210_CR22","doi-asserted-by":"crossref","unstructured":"Fontugne R, Borgnat P, Abry P, Fukuda K (2010) Mawilab: combining diverse anomaly detectors for automated anomaly labeling and performance benchmarking. In: Proceedings of the 6th international conference, ACM, p 8","DOI":"10.1145\/1921168.1921179"},{"issue":"18","key":"210_CR23","doi-asserted-by":"publisher","first-page":"3823","DOI":"10.1002\/dac.3823","volume":"31","author":"M \u015eim\u015fek","year":"2018","unstructured":"\u015eim\u015fek M, \u015eent\u00fcrk A (2018) Fast and lightweight detection and filtering method for low-rate tcp targeted distributed denial of service (lddos) attacks. Int J Commun Syst 31(18):3823","journal-title":"Int J Commun Syst"},{"key":"210_CR24","doi-asserted-by":"publisher","first-page":"234","DOI":"10.1016\/j.comnet.2019.01.007","volume":"150","author":"E Cambiaso","year":"2019","unstructured":"Cambiaso E, Chiola G, Aiello M (2019) Introducing the slowdrop attack. Comput Netw 150:234\u2013249","journal-title":"Comput Netw"},{"issue":"3","key":"210_CR25","doi-asserted-by":"publisher","first-page":"285","DOI":"10.1049\/iet-ifs.2018.5097","volume":"13","author":"M Yue","year":"2019","unstructured":"Yue M, Wu Z, Wang J (2019) Detecting ldos attack bursts based on queue distribution. IET Inf Secur 13(3):285\u2013292","journal-title":"IET Inf Secur"},{"key":"210_CR26","doi-asserted-by":"publisher","first-page":"64","DOI":"10.1016\/j.comnet.2019.01.031","volume":"152","author":"Z Wu","year":"2019","unstructured":"Wu Z, Pan Q, Yue M, Liu L (2019) Sequence alignment detection of tcp-targeted synchronous low-rate dos attacks. Comput Netw 152:64\u201377","journal-title":"Comput Netw"},{"issue":"2","key":"210_CR27","doi-asserted-by":"publisher","first-page":"3449","DOI":"10.1002\/dac.3449","volume":"31","author":"M Yue","year":"2018","unstructured":"Yue M, Liu L, Wu Z, Wang M (2018) Identifying ldos attack traffic based on wavelet energy spectrum and combined neural network. Int J Commun Syst 31(2):3449","journal-title":"Int J Commun Syst"},{"issue":"13","key":"210_CR28","doi-asserted-by":"publisher","first-page":"2312","DOI":"10.1016\/j.comnet.2005.09.016","volume":"50","author":"H Sun","year":"2006","unstructured":"Sun H, Lui JC, Yau DK (2006) Distributed mechanism in detecting and defending against the low-rate tcp attack. Comput Netw 50(13):2312\u20132330","journal-title":"Comput Netw"},{"key":"210_CR29","unstructured":"Cao Y, Han L, Zhao X, Pan X (2019) Accflow: Defending against the low-rate tcp dos attack in wireless sensor networks. arXiv preprint arXiv:1903.06394"},{"issue":"4","key":"210_CR30","doi-asserted-by":"publisher","first-page":"2993","DOI":"10.1002\/dac.2993","volume":"30","author":"X Zhang","year":"2017","unstructured":"Zhang X, Wu Z, Chen J, Yue M (2017) An adaptive kpca approach for detecting ldos attack. Int J Commun Syst 30(4):2993","journal-title":"Int J Commun Syst"},{"key":"210_CR31","doi-asserted-by":"crossref","unstructured":"Wu X, Tang D, Tang L, Man J, Zhan S, Liu Q (2018) A low-rate dos attack detection method based on hilbert spectrum and correlation. In: 2018 IEEE smartworld, ubiquitous intelligence & computing, advanced & trusted computing, scalable computing & communications, cloud & big data computing, internet of people and smart city innovation (SmartWorld\/SCALCOM\/UIC\/ATC\/CBDCom\/IOP\/SCI), IEEE, pp 1358\u20131363","DOI":"10.1109\/SmartWorld.2018.00236"},{"key":"210_CR32","doi-asserted-by":"publisher","first-page":"44","DOI":"10.1016\/j.ipl.2018.06.001","volume":"138","author":"N Agrawal","year":"2018","unstructured":"Agrawal N, Tapaswi S (2018) Low rate cloud ddos attack defense method based on power spectral density analysis. Inf Process Lett 138:44\u201350","journal-title":"Inf Process Lett"},{"key":"210_CR33","doi-asserted-by":"publisher","first-page":"32853","DOI":"10.1109\/ACCESS.2019.2903816","volume":"7","author":"H Chen","year":"2019","unstructured":"Chen H, Meng C, Shan Z, Fu Z, Bhargava BK (2019) A novel low-rate denial of service attack detection approach in zigbee wireless sensor network by combining hilbert-huang transformation and trust evaluation. IEEE Access 7:32853\u201332866","journal-title":"IEEE Access"},{"key":"210_CR34","doi-asserted-by":"crossref","unstructured":"Yan Y, Tang D, Zhan S, Dai R, Chen J, Zhu N (2019) Low-rate dos attack detection based on improved logistic regression. In: 2019 IEEE 21st international conference on high performance computing and communications; IEEE 17th international conference on smart city; IEEE 5th international conference on data science and systems (HPCC\/SmartCity\/DSS), IEEE, pp 468\u2013476","DOI":"10.1109\/HPCC\/SmartCity\/DSS.2019.00076"},{"key":"210_CR35","doi-asserted-by":"crossref","unstructured":"Zhang D, Tang D, Tang L, Dai R, Chen J, Zhu N (2019) Pca-svm-based approach of detecting low-rate dos attack. In: 2019 IEEE 21st international conference on high performance computing and communications; IEEE 17th international conference on smart city; IEEE 5th international conference on data science and systems (HPCC\/SmartCity\/DSS), IEEE, pp 1163\u20131170","DOI":"10.1109\/HPCC\/SmartCity\/DSS.2019.00164"},{"key":"210_CR36","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2019.12.034","author":"D Tang","year":"2020","unstructured":"Tang D, Tang L, Dai R, Chen J, Li X, Rodrigues JJ (2020) Mf-adaboost: Ldos attack detection based on multi-features and improved adaboost. Future Gener Comput Syst. https:\/\/doi.org\/10.1016\/j.future.2019.12.034","journal-title":"Future Gener Comput Syst"},{"issue":"4","key":"210_CR37","first-page":"930","volume":"20","author":"Y-X He","year":"2009","unstructured":"He Y-X, Cao Q, Liu T, Han Y, Xiong Q (2009) A low-rate dos detection method based on feature extraction using wavelet transform. J Softw 20(4):930\u2013941","journal-title":"J Softw"},{"key":"210_CR38","doi-asserted-by":"crossref","unstructured":"Zhang T, Ramakrishnan R, Livny M (1996) Birch: an efficient data clustering method for very large databases. In: ACM sigmod record, vol 25. ACM, pp 103\u2013114","DOI":"10.1145\/235968.233324"},{"key":"210_CR39","unstructured":"Chen Y, Hwang K, Kwok Y-K (2005) Filtering of shrew ddos attacks in frequency domain. In: The IEEE conference on local computer networks 30th anniversary (LCN\u201905) L, IEEE, p 8"},{"issue":"5","key":"210_CR40","doi-asserted-by":"publisher","first-page":"3505","DOI":"10.1002\/dac.3505","volume":"31","author":"X Zhang","year":"2018","unstructured":"Zhang X, Wu Z, Zhang J, Chen J (2018) An adaptive network traffic prediction approach for ldos attacks detection. Int J Commun Syst 31(5):3505","journal-title":"Int J Commun Syst"}],"container-title":["Human-centric Computing and Information Sciences"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s13673-020-0210-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s13673-020-0210-9\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s13673-020-0210-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,7,30]],"date-time":"2021-07-30T11:59:48Z","timestamp":1627646388000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1186\/s13673-020-0210-9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,2,6]]},"references-count":40,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2020,12]]}},"alternative-id":["210"],"URL":"https:\/\/doi.org\/10.1186\/s13673-020-0210-9","relation":{},"ISSN":["2192-1962"],"issn-type":[{"value":"2192-1962","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,2,6]]},"assertion":[{"value":"17 May 2019","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"16 January 2020","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"6 February 2020","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"The authors declare that they have no competing interests.","order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"6"}}