DocumentCode :
2198505
Title :
DDoS Detection using host-network based metrics and mitigation in experimental testbed
Author :
Devi, B. S Kiruthika ; Preetha, G. ; Shalinie, S. Mercy
Author_Institution :
Dept. of Comput. Sci. & Eng., Anna Univ., Madurai, India
fYear :
2012
fDate :
19-21 April 2012
Firstpage :
423
Lastpage :
427
Abstract :
Distributed Denial of Service (DDoS) attacks is very recent and popular devastating attack in the field of cyber society. Flooding DDoS attacks produce adverse effects for critical infrastructure availability, integrity and confidentiality. Current defense approaches cannot efficiently detect and filter out the attack traffic in real time. Online analysis of real time attack traffic and their impact and degradation of host and network based performance metrics becomes very essential. So, online measurement of these network performance metrics itself acts as an Intrusion detection system. The anomalies are the inference for network security analyst to suspect whether the network is under attack or not. Based on the assumption that the attacker flows are very aggressive than the legitimate users the proposed work provides sufficient bandwidth to genuine users during flooding DDoS attack. The Interface Based Rate Limiting (IBRL) algorithm proposed in this paper is used to mitigate the identified DDoS attacks. The implementation is carried out on an experimental testbed build up on Linux machines and Virtual routers. The experimental results show that there is considerable increase in the host and network based performance metrics for legitimate users even under DoS and DDoS attacks.
Keywords :
Linux; computer network security; telecommunication traffic; DDoS attack; DDoS detection; IBRL; Linux machines; critical infrastructure availability; critical infrastructure confidentiality; critical infrastructure integrity; cyber society; distributed denial of service attacks; experimental testbed; host-network based metrics; host-network based mitigation; interface based rate limiting algorithm; network performance metrics online measurement; real time attack traffic online analysis; virtual routers; Bandwidth; Computer crime; Internet; Limiting; Measurement; Monitoring; Throughput; Distributed Denial of Service attack; host and network based performance metrics; rate limiting; virtual router;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Recent Trends In Information Technology (ICRTIT), 2012 International Conference on
Conference_Location :
Chennai, Tamil Nadu
Print_ISBN :
978-1-4673-1599-9
Type :
conf
DOI :
10.1109/ICRTIT.2012.6206744
Filename :
6206744
Link To Document :
بازگشت