Information theory-based entropy and divergence metrics are widely used for DDoS attack detection. Entropy represents the randomness in the network features, whereas a divergence metric represents the similarity of two probability distributions. The concept of uncertainty’s measurement is coined initially by Claude Shannon in 1948. The information distance or divergence metric calculated using different probability distributions of traffic flows used to find the abnormality of network traffic. By using the entropy measure, it can be seen how the current network behaviour deviates from normal network behaviour, which leads to the detection of a DDoS attack. This is a comparison between the DDoS defence approaches using entropy and divergence metrics.
ORKG Comparisons have changed. We have added new features and improved the user interface. Comparisons might look slightly different, but the comparison data itself remains unchanged.
Singh, J., & Behal, S. (2020). Detection and mitigation of DDoS attacks in SDN: A comprehensive review, research challenges and future directions. Computer Science Review, 37, 100279.