DocumentCode :
121221
Title :
Detecting and preventing DDoS attacks in botnets by the help of self triggered black holes
Author :
Sadeghian, Alireza ; Zamani, Mahdi
Author_Institution :
Adv. Inf. Sch., Univ. Teknol. Malaysia, Kuala Lumpur, Malaysia
fYear :
2014
fDate :
10-12 Feb. 2014
Firstpage :
38
Lastpage :
42
Abstract :
Among various types of computer threats, botnet is the most serious one against cyber security as they provide several illegal activities such as denial of service attacks, spamming, click fraud and other type of espionage activities. A botnet is a network of infected computers called bots which are under the control of one person known as Botmaster. Botmaster will have full control over the compromised machines from the command and control (C&C) channels, which allow Botmaster to update and add new features to the botnet. Distributed Denial of Service is one of deadliest attacks in history of network security which is take place by botnets. Until now many different solutions against this attack are proposed. One of these techniques is the Remote Triggered black hole filtering for stopping DDoS attacks by botnets. The main drawback of this technique is that the trigger is located at the victim premises and in case of an attack the network between trigger and routers will be saturated by attack traffic. Therefore the trigger cannot effectively communicate with the router to ask them to stop the traffic from the source IP. This paper proposes an improved framework to do the black hole filtering on the edge of internet service provider without need of the trigger (Self Triggered). The most tangible improvements in our framework are stopping DDoS attacks before entering into victim premises, ease of tracking and reporting the compromised machines for further cleanings.
Keywords :
IP networks; Internet; computer network security; invasive software; Botmaster; C&C channels; DDoS attacks; IP network; Internet service provider; botnets; command and control channels; distributed denial of service; network security; remote triggered black hole filtering; telecommunication router; Computer crime; Computers; Filtering; IP networks; Internet; Malware; Black hole filtering; Bot; Botnet; Cyber Security; DDoS; Malware;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computer Aided System Engineering (APCASE), 2014 Asia-Pacific Conference on
Conference_Location :
South Kuta
Print_ISBN :
978-1-4799-4570-2
Type :
conf
DOI :
10.1109/APCASE.2014.6924468
Filename :
6924468
Link To Document :
بازگشت