DocumentCode :
1918827
Title :
Procedure for detection of and response to Distributed Denial of Service cyber attacks on complex enterprise systems
Author :
Hershey, Paul C. ; Silio, Charles B., Jr.
Author_Institution :
Raytheon Intell. & Inf. Syst., Dulles, VA, USA
fYear :
2012
fDate :
19-22 March 2012
Firstpage :
1
Lastpage :
6
Abstract :
The increasing frequency, rising costs, and growing sophistication of cyber attacks on DoD, agency and commercial enterprise systems are dramatically reducing the quality of end-user services and compromising mission effectiveness. Of those attacks, one of the more severe is Distributed Denial-of-Service (DDoS) through which an attacker can disrupt, and possibly shutdown, local network enclaves and global net-centric enterprise systems. Previous attempts to overcome this threat include intrusion detection and prevention systems (IDS/IPS), firewalls, and packet scanning software. However, none of these approaches individually achieves prevention or provides sufficient countermeasures to overcome and resolve DDoS threats. This paper presents a detailed procedure for identifying both the on-set of DDoS attacks and corresponding countermeasures to prevent or limit their effects. This procedure applies a hybrid approach that adapts to changing DDoS attack scenarios. Concrete examples provided for each step of the procedure identify the key tools to proactively prevent or respond to DDoS events. Simulated results demonstrate the effectiveness of the procedure for a representative DDoS attack scenario.
Keywords :
business data processing; computer network security; DDoS attack scenario; DDoS events; DDoS threats; DoD; complex enterprise systems; detection procedure; distributed denial of service cyber attacks; response procedure; Computer crime; Correlation; Delay; Quality of service; Throughput;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Systems Conference (SysCon), 2012 IEEE International
Conference_Location :
Vancouver, BC
Print_ISBN :
978-1-4673-0748-2
Type :
conf
DOI :
10.1109/SysCon.2012.6189438
Filename :
6189438
Link To Document :
بازگشت