<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Method of Traffic Monitoring for DDoS Attacks Detection in e-Health systems and networks</article-title>
      </title-group>
      <fpage>0000</fpage>
      <lpage>0002</lpage>
      <abstract>
        <p>eHealth is a complex system that will be gradually introduced in Ukraine over next several years . It is very efficient system that brings a lot of possibilities in the future. But there are a lot of potential problems in deployment of such protected systems. One of the most common problem is the cybersecurity provision. Cybersecurity is one of the key problems of modern society. Quickest detection of attacks on computer networks is the basis for successful operation of various spheres. This paper deals with the problem of distributed denial of service (DDoS) attacks detection procedure synthesis based on Neyman-Pearson criterion with a fixed sample size. The prerequisite for the synthesis of such procedure was the experimental study of the statistical characteristics of traffic consumption in the absence and presence of DDoS attack. The suitability of proposed procedure is confirmed both experimentally and by simulation.</p>
      </abstract>
      <kwd-group>
        <kwd>1 National aviation univercity</kwd>
        <kwd>Kyiv</kwd>
        <kwd>Ukraine</kwd>
        <kwd>03058</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>1.1</p>
    </sec>
    <sec id="sec-2">
      <title>Introduction</title>
      <sec id="sec-2-1">
        <title>Problem of DoS attacks</title>
        <p>
          At the end of January 2018, the global media agency We Are Social and the developer
of the platform for managing social networks HootSuite presented a report according to
which more than four billion people around the world use the Internet. The number of
Internet users by the end of 2018 amounted to 4.021 billion (53% of the world’s
population), which is 7% more compared to the same period in 2017 [
          <xref ref-type="bibr" rid="ref1">1</xref>
          ].
        </p>
        <p>
          If in 2015 43% of the world population (3.2 billion people) had access to the network
(in 1995 this figure was 1%), then by 2020 the Internet will be available for 60% [
          <xref ref-type="bibr" rid="ref2">2</xref>
          ].
        </p>
        <p>
          The number of sensors and devices connected to the Internet of Things in the world
in 2018 will be 21 billion, and by 2022 will exceed 50 billion, according to a study by
Juniper Research [
          <xref ref-type="bibr" rid="ref3">3</xref>
          ].
        </p>
        <p>
          At the same time, the global network is becoming increasingly dangerous, as it
becomes more and more easier to organize all categories of cyberattacks on the most
popular resources as well as on critical infrastructure. One of the most common attacks is
threat realization directed to the denial of service (Denial of Service, DoS) [
          <xref ref-type="bibr" rid="ref4">4</xref>
          ].
        </p>
        <p>The most common methods of DoS attacks are SYN-DDoS, TCP-DDoS,
HTTPDDoS. Also popular attacks are strong UDP attacks with amplification, which came into
use a few years ago, but still remain relevant due to the ease of implementation, and the
ability to provide tremendous power.</p>
        <p>
          They are increasingly organized to block the operation of individual sites and entire
information systems. With the increasing the number of devices connected to the Internet
network (IoE concept – Internet of everything [
          <xref ref-type="bibr" rid="ref5">5</xref>
          ]), the threat from distributed DoS
attacks (DDoS) is growing. They arise from the bot-nets – networks that consist of infected
devices that are able to generate queries aimed at exhausting the resources of network
devices or entire information networks.
        </p>
        <p>The point of the DDoS attack is that there is a scarce resource in the victim’s network
infrastructure, the depletion of which causes a denial of service.</p>
        <p>The most well-known recent attacks were aimed at exhausting the bandwidth of the
site’s connection to the Internet.</p>
        <p>
          However, the development of broadband access technologies and cloud computing
complicate this task. But, to all appearances, the intruders are not intimidated by the
difficulties, and they are trying to organize more and more powerful attacks. In the
spring of this year, the infrastructure of one cloud provider was attacked with a capacity
of 400 Gbit / s, but more large-scale shares are possible as well [
          <xref ref-type="bibr" rid="ref6">6</xref>
          ]. In these conditions
for providers, owners of information systems and simple users, it is important to
determine the occurrence of the above attacks in a timely manner, and then counteract them.
1.2
        </p>
      </sec>
      <sec id="sec-2-2">
        <title>DoS attacks in e-Health concept</title>
        <p>"Electronic health" (eHealth) is a complex system that will be gradually introduced over
several years. In the future, the eHealth system will enable everyone to quickly get their
medical information, and to doctors - to correctly diagnose with a view of a coherent
picture of the patient's health.</p>
        <p>In Ukraine, the system will consist of a central component (CBC). It will be
responsible for centralized storage and processing of information - and medical information
systems (MIS), which hospitals and clinics can choose on the market and establish
themselves.</p>
        <p>Because eHealth systems are based on the use of public network solutions (mobile
networks, computer networks, Internet), all the problems that may arise in them will
affect and affect the work of the system as a whole. DoS attacks because of their
simplicity of implementation can become widespread in these systems. At the same time,
denial of access can be both a cause of both banal economic losses and even human
casualties. Therefore, protection from this type of attack and their early detection is a
very urgent task of the introduction of eHealth systems.</p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>Modern Literature Analysis</title>
      <p>
        Where automated means of attack are used, automated security measures can always be
developed. In particular, some manufacturers produce special devices that can block
unproductive requests. For example, such devices are in the arsenal of following
companies: Cisco [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ], Arbor Networks [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ], CloudShield [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ] and other vendors. Such solutions
filter the spurious traffic at high speeds and designed primarily for providers – they
should be installed not in the front of the corporate site, but as close to the source of
unproductive requests.
      </p>
      <p>
        According to the document of the National Institute of Standards and Technology
(NIST, USA) SP800-94 [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ], and the latest research of cybersecurity experts, intrusion
detection and prevention system (IDPS) is the best way to detect DoS attacks, because
IDPS is based on the method of detecting anomalies (Anomaly-Based Detection) and a
method of network monitoring (Network Behavior Analysis, NBA) [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ].
      </p>
      <p>
        The task of DoS attacks detection (in this case, it is reduced to the task of classifying
data) can be effectively solved using artificial neural networks. The advantage of this
method is the ability to detect an attack without knowing specific signatures. However,
there are also disadvantages – a large number of false signals in case of unpredictable
network activity, along with time spent for the learning the system, during which
characteristics of normal behavior are determined [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ]. In [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ] structural model for detecting
slow DoS attacks proposed. In [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ] are considered the issues of error reduction and early
detection of DDoS-attacks by statistical methods taking into account seasonality;
effective allocation of periods of seasonality.
      </p>
      <p>
        For each of the above methods, the main parameters for analysis can be [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ]: number
of requests for a certain period; receipt of requests speed; number of requests from a
particular source or from a particular network; number of requests to a specific
destination (for a web server this is a specific script); time between requests and other various
network activity parameters. In general, the presence of DDoS attack leads to a change
in the structure of the consumed traffic. In other words, the stationarity of observed
process is disturbed. Therefore, the problem of intrusions detection can be considered as
problem of quickest changepoint detection. The theory of changepoint detection was
described in [
        <xref ref-type="bibr" rid="ref15 ref16 ref17">15-17</xref>
        ]. In addition, in [
        <xref ref-type="bibr" rid="ref17">17</xref>
        ] the authors gave an example of the application
of CUSUM and Shiryaev-Roberts procedures for detection of network anomalies. Paper
[
        <xref ref-type="bibr" rid="ref18">18</xref>
        ] presents five methods for changepoint detection: density-estimation-based
changepoint detection, density-ratio-estimation-based changepoint detection, clustering-based
changepoint detection, hybrid changepoint detection. Authors showed that hybrid
method performs best for different types of changepoints.
      </p>
      <p>
        Another example of CUSUM algorithm to detect cloud DDoS flooding attacks was
considered in [
        <xref ref-type="bibr" rid="ref19">19</xref>
        ]. Detection accuracy for different traffic flows for this method varies
within 76-100 %. Comparison between two of the most promising anomaly detection
methods (CUSUM-based and entropy-based) was presented in [
        <xref ref-type="bibr" rid="ref20">20</xref>
        ]. In [
        <xref ref-type="bibr" rid="ref21">21</xref>
        ] authors
declared that additional to CUSUM entropy approach improves detection efficiency and
detects attacks with high probability and low false alarms.
      </p>
      <p>
        Papers [
        <xref ref-type="bibr" rid="ref22 ref23">22, 23</xref>
        ] deals with DDoS attack detection using artificial intelligence
techniques. According to [
        <xref ref-type="bibr" rid="ref23">23</xref>
        ] accuracy for this method of intrusions detection is about 94%.
Paper [
        <xref ref-type="bibr" rid="ref24">24</xref>
        ] concentrates on computer tool with complete environment of network and
attacks on the network with detection of the attacks using simulation. This research can
be used to improve the efficiency of attack detection. Also the analysis of the up-to-date
literature shows that there are other methods for intrusions detection, such as those
discussed in [25; 26].
      </p>
    </sec>
    <sec id="sec-4">
      <title>Problem statement</title>
      <p>The practice of computer networks using shows that quickest detection of intrusions is
the basis for successful operation of various industries. Fulfilled literature analysis
allows us to conclude that sufficient attention is paid to the questions of detecting attacks
on computer networks. There are also a large number of detection algorithms. However,
the efficiency of attacks detection procedures can still be increased.</p>
      <p>In the general case, the efficiency measure can be considered as a function of the
following form
</p>
      <p>Ef  f (td , D, Pfa ,U,C / A) ,

where A is a set of algorithms for statistical data processing, td is a time interval from
the moment of the beginning of the attack to the moment of its detection, D is a
probability of correct detection, Pfa is a probability of false alarm, U is a computational
requirements for the correct operation of the detection algorithm, C is function of
penalties due to late detection of an attack or false detection.</p>
      <p>The function f () must establish such dependence that its maximum should be equal
one if probability of correct detection is one and td  0 . If D  0 , Pfa increases, and
td increases, the function f () must decrease to zero.</p>
      <p>The purpose of this paper is the synthesis of such algorithm for detection of attacks
on computer networks, in which the maximum efficiency measure is provided for the
given requirements on the parameters D , Pfa , td and U . In other words, it is necessary
to provide</p>
      <p></p>
      <p>Ef  sup0  Ef  1 A : td  td* , D  D*, Pfa  Pf*a  ,
where td* , D , Pf*a are requirements on the parameters.</p>
      <p>*
It should also be noted that the basis for the synthesis of the algorithm for detecting
attacks will be the experimental study described below. The analysis of the detection
algorithm will also be performed by statistical modeling.
4</p>
    </sec>
    <sec id="sec-5">
      <title>Experimental Study</title>
      <p>In this research study the following network was designed (Fig. 1). This network consists
of four laptops, server-laptop, router and switch.</p>
      <p>To analyze the traffic, the Wireshark program was used.</p>
      <p>After starting to capture traffic, Wireshark captures network packets in real time and
displays them in the user interface window. The example of packet transfer time series
in the local network during 5 minutes in case of information presence without DDoS
attacks is shown in the Fig. 2.</p>
      <p>Let’s consider the simulation procedure for a possible DDoS attack on the server. To
do this, we will ping our server from four laptops at the same time, thereby simulating a
ping flood attack. The DDoS attack is carried out in such way: we pass the packet of 32
bytes to the server and receive an average response of 20 ms TTL (time to live). In the
general case we sent 118 packages from each attacking laptop.</p>
      <p>The example of packet transfer time series in the local network during 6 minutes in
case of DDoS attacks presence is shown in the Fig. 3. On the graph we can see increasing
in the number of packets per second, which means the beginning of the attack, and the
decrease in the number of packets, that signs the end of the attack.</p>
    </sec>
    <sec id="sec-6">
      <title>Detection procedure synthesis</title>
      <p>Synthesis of the procedure for attacks detection we can perform on the basis of
NeymanPearson criterion. In this case, we assume that the sample has a fixed size n .</p>
      <p>The initial data for the analysis are the results of measurements of the traffic packets
per second xi obtained using Wireshark program. We suppose that xi is a random
variable with independent values described by an identical probability density function
(PDF) in case of attacks absence. In order to determine the nature of the probability
density function for xi , we use the results of an experimental study. An example of an
experimentally obtained PDF for the case of five minutes of traffic monitoring without
attacks is shown in the Fig. 4.</p>
      <p>Mean quantity of traffic packets per second is equal to 2.71. Let’s check the
hypothesis about the exponential distribution of random variable xi . To do this we use
chisquare test.</p>
      <p>F
D
P
f (x)
x
and this value is less than threshold value 2th  11.341, so the hypothesis about
exponential PDF is accepted with a significance level equal to 0.01.</p>
      <p>Accordingly, the probability density function of traffic packets per second for
considered example is the following</p>
      <p>f0 (x)  0.369e0.369xh(x) ,
where h(x) is Heaviside step function.</p>
      <p>An example of experimentally obtained PDF for the case of two minutes of DDoS
attacks is shown in the Fig. 5.</p>
      <p>F
D
P
f ( x)
x</p>
      <p>Packets per second</p>
      <p>To determine the nature of PDF in the Fig. 5, the following assumption was made.
In the case of attack from a single computer, the traffic flow PDF is exponential. In our
experiment, an attack was carried out from four computers. Therefore, the
experimentally obtained PDF can be represented as a sum of four exponentially distributed random
variables. Such PDF is described by chi-square distribution. For this particular case one
attack was characterized by exponential distribution with parameter   0.462 . So, PDF
in the Fig. 5 can be described by following equation</p>
      <p>f1(x)  7.563103 x3e0.461xh(x) .</p>
      <p>Let’s check how experimental data coincide with PDF f1(x) . According to
chisquare test we can obtain</p>
      <p>2
calc  10.403 ,
and this value is less than threshold value 2th  11.341, so the hypothesis about PDF
f1(x) type is accepted with a significance level equal to 0.01.</p>
      <p>According to Neyman-Pearson criterion we can write the likelihood ratio
(xi , n, k, ) 
(xi / H )</p>
      <p>1 ,
(xi / H0 )
where (xi / H1) is a likelihood function for alternative H1 (there is DDoS attack in
the traffic flow); (xi / H0 ) is a likelihood function for hypothesis H0 (the traffic flow
doesn’t contain DDoS attack).</p>
      <p>Likelihood functions can be represented as
n
(xi / H0 )   f0 (xi / H0 ) .</p>
      <p>i1
According to obtained experimental results we can write
f0 (xi / H0 )  exi for i[1, n] ,
k exi ink  46xi3 exi   ink  46xi3 exi  
n n n
 exi  exi   exi 
i1
ik</p>
      <p>ik
 n  36xi3   63(nnkk11) n xi3.</p>
      <p>ik   ik
Logarithm of likelihood ratio</p>
      <p> 3(nk 1) n  3
ln (xi , n, k, )  ln 6nk 1 ik xi3    (n  k 1) ln 6
Let  j  ln (xi , n, j, ) for є  j[1, n] is a decisive statistic. So
n
 3 ln xi.</p>
      <p>ik
 j  (n  j 1) ln
3
6</p>
      <p>n
 3 ln xi .</p>
      <p>i j</p>
      <p>It should be noted that the statistics  j correspond to the so-called CUSUM
algorithm. In addition, to avoid the uncertainty of the logarithmic function in the decisive
statistics, all zero packets measurements were replaced by ones.</p>
      <p>Decision-making scheme was accepted as follows. Each sample of the decisive
statistics  j is compared with the threshold V . The threshold was calculated by statistical
modeling in such a way that to provide a given probability of correct detection D at a
certain level of DDoS attacks intensity. The decision about DDoS attack presence is
taken at decisive statistics first exceeding the threshold. If  j  V , then we make
decision about DDoS attack detection and otherwise about its absence.
6</p>
    </sec>
    <sec id="sec-7">
      <title>Detection procedure analysis</title>
      <p>To assess the accuracy of DDoS attacks detection, let’s perform an analysis of
considered procedure. Fig. 6 presents the realization of decisive statistic for data shown in Fig.
3.</p>
      <sec id="sec-7-1">
        <title>Number of sample</title>
        <p>As can be seen in the Fig. 6, the decisive statistics  j exceed the threshold V .
Therefore, we make the correct decision about the presence of DDoS attack in the traffic flow.
In addition max(  j ) corresponds to time moment of attack beginning.</p>
        <p>It should be noted that the analysis of such procedures with further estimation of
unknown parameters was considered by the authors in [27; 28].</p>
        <p>To construct the operating characteristic, the simulation was used. The obtained
dependence of probability of correct detection of intrusions on the quantity of attacking
computers is shown in the Fig. 7.</p>
        <p>s
c
ttiti
s
a
s
e
v
ii
s
c
e
D
 j</p>
        <p>Threshold
j</p>
      </sec>
      <sec id="sec-7-2">
        <title>Quantity of attacking computers</title>
        <p>l</p>
        <p>Conclusion
eHealth is a complex system that will be gradually introduced over several years. It is
very efficient project that will bring a lot of possibilities in the future. But there are a lot
of potential problems in development and deployment of such high-level protected
systems. One of the most common problem is the huge amount of DoS attacks in the
Internet. DoS attacks can damage servers, storages etc. That’s why it is very important to
develop novel methods of Traffic Monitoring for DDoS Attacks Detection in e-Health
systems and networks.</p>
        <p>The problem of synthesis and analysis of the procedure for DDoS attacks detection
was considered in this paper. The synthesis of the detection procedure was carried out
on the basis of Neyman-Pearson criterion. The analysis was performed by simulation.
The proposed procedure for attacks detection can be considered as a type of CUSUM
algorithm. Maximum of decisive statistic corresponds to time moment of attack
beginning.</p>
        <p>The simulation results showed that the detection procedure has high accuracy at low
computational capability. In the considered example, the probability of correct detection
is 0.95 in case of attacks from four computers and approximately 1 in case of attacks
from five computers and probability of false alarm Pfa  0 . The requirements for td
can be provided by using online calculations in the moving window by selecting the
appropriate sample size.</p>
        <p>The results of the research study can be used for various computer network systems
security against DDoS attacks.</p>
      </sec>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <surname>McDonald</surname>
            ,
            <given-names>N.</given-names>
          </string-name>
          : Digital In 2018:
          <article-title>World's internet users pass the 4 billion mark, - We Are Social USA (</article-title>
          <year>2018</year>
          ) https://wearesocial.com/us/blog/2018/01/global-digital
          <source>-report-2018 last accessed 20/10/2018</source>
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <given-names>ICT</given-names>
            <surname>Facts</surname>
          </string-name>
          and
          <article-title>figures</article-title>
          <year>2017</year>
          (
          <year>2017</year>
          ) https://www.itu.int/ en/ITU-D/Statistics/Documents/facts/ICTFactsFigures2017.pdf last accessed
          <volume>20</volume>
          /10/2018
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3. IoT Connections to grow 140%
          <article-title>to hit 50 billion by 2022, as edge computing accelerates ROI (</article-title>
          <year>2018</year>
          ) https://www.juniperresearch.com/press/press-releases/iot-connections-to-grow-140
          <string-name>
            <surname>-</surname>
          </string-name>
          to-hit-50
          <source>-billion last accessed</source>
          <volume>20</volume>
          /10/2018
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4. DDOS attack scripts (
          <year>2018</year>
          ) https://www.incapsula.com/ddos/ddos-attack-scripts.
          <source>html last accessed</source>
          <volume>20</volume>
          /10/2018
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5. Internet of Everything (
          <year>2018</year>
          ) https://newsroom.cisco.com/ioe last accessed
          <volume>20</volume>
          /10/2018
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <surname>Roberts</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>Public cloud service definition</article-title>
          ,
          <source>Version</source>
          <volume>2</volume>
          .9 (
          <issue>2018</issue>
          ) https://www.vmware.com/ content/dam/digitalmarketing/vmware/en/pdf/vcat/vmware
          <article-title>-public-cloud-servicedefinition</article-title>
          .
          <source>pdf last accessed</source>
          <volume>20</volume>
          /10/2018
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7.
          <article-title>Configuring denial of service protection (</article-title>
          <year>2018</year>
          ) https://www.cisco.com/c/en/us/td/docs/ switches/lan/catalyst6500/ios/12-2SX/configuration/guide/book/dos.pdf last accessed
          <volume>20</volume>
          /10/2018
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <given-names>Arbor</given-names>
            <surname>Networks</surname>
          </string-name>
          <article-title>DDoS attack protection solutions (</article-title>
          <year>2017</year>
          ) https://www.netscout.com/sites/default/files/2017-09/SB_DDoSAttackProtection_EN.pdf last accessed
          <volume>20</volume>
          /10/2018
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9.
          <article-title>Protect against DDoS attack (</article-title>
          <year>2018</year>
          ) https://www.cloudflare.com/ddos/ last accessed 20/10/2018
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10.
          <string-name>
            <surname>Scarfone</surname>
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Mell</surname>
            <given-names>P.</given-names>
          </string-name>
          :
          <article-title>Guide to Intrusion Detection and Prevention Systems (IDPS) Recommendations of the National Institute of Standards and Technology (</article-title>
          <year>2007</year>
          ) https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-
          <fpage>94</fpage>
          .pdf
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          11. NIST Special Publication 800-
          <fpage>94</fpage>
          . Guide to Intrusion Detection and Prevention
          <string-name>
            <surname>Systems</surname>
          </string-name>
          (
          <year>2007</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          12.
          <string-name>
            <surname>Cannady</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Mahaffey</surname>
            ,
            <given-names>J.:</given-names>
          </string-name>
          <article-title>The Application of Artificial Neural Networks to Misuse Detection: Initial Results</article-title>
          .
          <source>In: 1998 National Information Systems Security Conference (NISSC'98)</source>
          , pp.
          <fpage>443</fpage>
          -
          <lpage>456</lpage>
          .
          <string-name>
            <surname>Arlington</surname>
          </string-name>
          (
          <year>1998</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          13.
          <string-name>
            <surname>Ruban</surname>
            ,
            <given-names>I.V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Pribylnov</surname>
            ,
            <given-names>D.V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Loshakov</surname>
            ,
            <given-names>E.S.:</given-names>
          </string-name>
          <article-title>Method of Identifying a Low-speed Attack of Type «Failure to Maintenance»</article-title>
          .
          <source>Science and Technology of the Air Forces of the Armed Forces of Ukraine</source>
          ,
          <volume>4</volume>
          (
          <issue>13</issue>
          ),
          <fpage>85</fpage>
          -
          <lpage>88</lpage>
          (in Russian) (
          <year>2013</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          14.
          <string-name>
            <surname>Ternovoi</surname>
            ,
            <given-names>O.S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Shatokhin</surname>
            ,
            <given-names>A.S.</given-names>
          </string-name>
          :
          <article-title>Early Detection of DDoS Attacks by Statistical Methods Taking into Account Seasonality</article-title>
          .
          <source>Mathematical substantiation and theoretical aspects of information security</source>
          ,
          <volume>1</volume>
          (
          <issue>25</issue>
          ) Volume
          <volume>1</volume>
          ,
          <fpage>104</fpage>
          -
          <lpage>107</lpage>
          (in Russian) (
          <year>2012</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          15.
          <string-name>
            <surname>Zhyhlyavskyi</surname>
          </string-name>
          , А.А.,
          <string-name>
            <surname>Kraskovskyi</surname>
            <given-names>A.E.</given-names>
          </string-name>
          :
          <article-title>Changepoint Detection of Random Processes in Problems of Radio Engineering, St</article-title>
          .
          <source>Petersburg: LU Publishing</source>
          ,
          <volume>224</volume>
          p.
          <article-title>(in Russian) (</article-title>
          <year>1998</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          16.
          <string-name>
            <surname>Shiryaev</surname>
            ,
            <given-names>A.N.</given-names>
          </string-name>
          : Stochastic Problems about Changepoint, Moscow: MCNMO,
          <volume>392</volume>
          p.
          <article-title>(in Russian) (</article-title>
          <year>2016</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          17.
          <string-name>
            <surname>Tartakovsky</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Nikiforov</surname>
            ,
            <given-names>I.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Basseville</surname>
            <given-names>M.</given-names>
          </string-name>
          :
          <string-name>
            <given-names>Sequential</given-names>
            <surname>Analysis</surname>
          </string-name>
          .
          <source>Hypothesis Testing and Changepoint Detection</source>
          , New York: Taylor &amp; Francis Group,
          <volume>580</volume>
          p. (
          <year>2015</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          18.
          <string-name>
            <surname>Jin</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Zhang</surname>
            ,
            <given-names>Z.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Chakrabarty</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Gu</surname>
            ,
            <given-names>X.</given-names>
          </string-name>
          :
          <article-title>Changepoint-based Anomaly Detection for Prognostic Diagnosis in a Core Router System</article-title>
          .
          <article-title>IEEE Transactions on computer-aided design of integrated circuits and systems</article-title>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>14</lpage>
          (
          <year>2018</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          19.
          <string-name>
            <surname>Osanaiye</surname>
            ,
            <given-names>O.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Choo</surname>
          </string-name>
          , K.
          <article-title>-</article-title>
          K.R.,
          <string-name>
            <surname>Dlodlo</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          :
          <article-title>Change-point Cloud DDoS Detection using Packet Inter-arrival Time</article-title>
          .
          <source>In: 8th Computer Science and Electronic Engineering (CEEC)</source>
          , pp.
          <fpage>204</fpage>
          -
          <lpage>209</lpage>
          .
          <string-name>
            <surname>Colchester</surname>
          </string-name>
          (
          <year>2016</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          20.
          <string-name>
            <surname>Callegari</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Pagano</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Giordano</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Berizzi</surname>
            ,
            <given-names>F.</given-names>
          </string-name>
          :
          <article-title>CUSUM-based and Entropy-based Network Anomaly Detection: an Experimental Comparison</article-title>
          .
          <source>In: 8th International Conference on the Network of the Future (NOF)</source>
          , pp.
          <fpage>132</fpage>
          -
          <lpage>134</lpage>
          . London (
          <year>2017</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          21.
          <string-name>
            <surname>Özçelik</surname>
          </string-name>
          , İ.,
          <string-name>
            <surname>Brooks</surname>
            ,
            <given-names>R.R.</given-names>
          </string-name>
          : Cusum - Entropy:
          <article-title>An efficient Method for DDoS Attack Detection</article-title>
          .
          <source>In: 4th International Istanbul Smart Grid Congress and Fair</source>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>5</lpage>
          . Istanbul (
          <year>2016</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          22.
          <string-name>
            <surname>Zhang</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          , Zhang,
          <string-name>
            <given-names>T.</given-names>
            ,
            <surname>Yu</surname>
          </string-name>
          ,
          <string-name>
            <surname>Z.</surname>
          </string-name>
          ;
          <source>DDoS Detection and Prevention based on Artificial Intelligence Techniques. In: 2017 3rd IEEE International Conference on Computer and Communications (ICCC)</source>
          , pp.
          <fpage>1276</fpage>
          -
          <lpage>1280</lpage>
          .
          <string-name>
            <surname>Chengdu</surname>
          </string-name>
          (
          <year>2017</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          23.
          <string-name>
            <surname>Hsieh</surname>
          </string-name>
          , C.-J.,
          <string-name>
            <surname>Chan</surname>
          </string-name>
          , T.-Y.:
          <article-title>Detection DDoS Attacks based on Neural-network using Apache Spark</article-title>
          .
          <source>In: International Conference on Applied System Innovation (ICASI)</source>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>4</lpage>
          . Okinawa (
          <year>2016</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          24.
          <string-name>
            <surname>Mishra</surname>
            ,
            <given-names>V.P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Shukla</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          :
          <article-title>Development of Simulator for Intrusion Detection System to Detect and Alarm the DDoS Attacks</article-title>
          .
          <source>In: International Conference on Infocom Technologies and Unmanned Systems (Trends and Future Directions) (ICTUS)</source>
          , pp.
          <fpage>803</fpage>
          -
          <lpage>806</lpage>
          .
          <string-name>
            <surname>Dubai</surname>
          </string-name>
          (
          <year>2017</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          25.
          <string-name>
            <surname>Alsirhani</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sampalli</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Bodorik</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          :
          <article-title>DDoS Attack Detection System: Utilizing Classification Algorithms with Apache Spark</article-title>
          .
          <source>In: 9th IFIP International Conference on New Technologies, Mobility and Security (NTMS)</source>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>7</lpage>
          . Paris (
          <year>2018</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          26.
          <string-name>
            <surname>Conti</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Gangwal</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Gaur</surname>
            ,
            <given-names>M.S.:</given-names>
          </string-name>
          <article-title>A Comprehensive and Effective Mechanism for DDoS Detection in SDN</article-title>
          .
          <source>In: IEEE 13th International Conference on Wireless and Mobile Computing, Networking and Communications (WiMob)</source>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>8</lpage>
          . Rome (
          <year>2017</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref27">
        <mixed-citation>
          27.
          <string-name>
            <surname>Solomentsev</surname>
            ,
            <given-names>O.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Zaliskyi</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Nemyrovets</surname>
            ,
            <given-names>Yu.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Asanov</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          :
          <source>Signal Processing in case of Radio Equipment Technical State Deterioration. In: Signal Processing Symposium 2015 (SPS</source>
          <year>2015</year>
          ), pp.
          <fpage>1</fpage>
          -
          <lpage>5</lpage>
          . Debe (
          <year>2015</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref28">
        <mixed-citation>
          28.
          <string-name>
            <surname>Solomentsev</surname>
            ,
            <given-names>O.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Zaliskyi</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kozhokhina</surname>
            ,
            <given-names>O.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Herasymenko</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          :
          <article-title>Reliability Parameters Estimation for Radioelectronic Equipment in Case of Change-point</article-title>
          .
          <source>In: Signal Processing Symposium</source>
          <year>2017</year>
          (SPSympo
          <year>2017</year>
          ), pp.
          <fpage>1</fpage>
          -
          <lpage>4</lpage>
          .
          <string-name>
            <given-names>Jachranka</given-names>
            <surname>Village</surname>
          </string-name>
          (
          <year>2017</year>
          )
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>