<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "https://jats.nlm.nih.gov/publishing/1.3/JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xml:lang="ru">
  <front xmlns:xlink="http://www.w3.org/1999/xlink">
    <journal-meta>
      <journal-id journal-id-type="elibrary">9004</journal-id>
      <journal-title-group>
        <journal-title>Problems of information security. Computer systems</journal-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Проблемы информационной безопасности. Компьютерные системы</trans-title>
        </trans-title-group>
      </journal-title-group>
      <issn pub-type="epub">2071-8217</issn>
    </journal-meta>
    <article-meta xmlns:xlink="http://www.w3.org/1999/xlink">
      <article-id pub-id-type="publisher-id">3</article-id>
      <article-id pub-id-type="doi">10.48612/jisp/6ed5-9p6x-uuf6</article-id>
      <title-group>
        <article-title>METHODOLOGY OF EARLY DETECTION OF DDOS ATTACKS TO PROTECT INFORMATION INFRASTRUCTURE OBJECTS</article-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Методика раннего выявления DDOS-атак для защиты объектов информационной инфраструктуры</trans-title>
        </trans-title-group>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <name>
            <surname>Glibovsky</surname>
            <given-names>Pavel</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
          <email>vka@mil.ru</email>
        </contrib>
        <contrib contrib-type="author">
          <name>
            <surname>Timashov</surname>
            <given-names>Pavel</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
          <email>vka@mil.ru</email>
        </contrib>
        <contrib contrib-type="author">
          <name>
            <surname>KOTENOK</surname>
            <given-names>Igor</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
        </contrib>
      </contrib-group>
      <aff id="aff1">Mozhaisky Military Aerospace Academy</aff>
      <pub-date publication-format="electronic" date-type="pub" iso-8601-date="2022-12-26">
        <day>26</day>
        <month>12</month>
        <year>2022</year>
      </pub-date>
      <issue>4</issue>
      <fpage>28</fpage>
      <lpage>34</lpage>
      <self-uri xmlns:xlink="http://www.w3.org/1999/xlink" content-type="pdf" xlink:href="https://jisp.spbstu.ru/userfiles/files/2022_4_short.pdf"/>
      <abstract xml:lang="en">
        <p>The approach of detecting the beginning of a DDoS attack by statistical methods, taking
into account seasonality, is considered. The standard setting of limits on the number of requests associated
with the occurrence of random triggers and various load of the web resource, depending
on the time of day and days of the week, has a number of disadvantages. To optimize the process,
it is proposed to use a floating estimate characterizing the current network activity based on the
standard deviation (RMS), as well as taking into account seasonal fluctuations. A k-means clustering
method for distributing client requests is proposed. The algorithm selects two clusters from
mixed traffic. The first is a set of legitimate requests, the second is a set of malicious requests. The
introduction of the proposed technique into the protection system, which takes into account the seasonality of DDoS attacks for various types of infrastructure objects, can increase the efficiency of
detecting such attacks without increasing resource intensity</p>
      </abstract>
      <kwd-group xml:lang="en">
        <kwd>DDoS attack</kwd>
        <kwd>standard deviation</kwd>
        <kwd>seasonal fluctuations</kwd>
        <kwd>k-means</kwd>
      </kwd-group>
    </article-meta>
  </front>
</article>
