DocumentCode
2592537
Title
Autonomous dynamic honeypot routing mechanism for mitigating DDoS attacks in DMZ
Author
Sardana, Anjali ; Joshi, R.C.
Author_Institution
Dept. of Electron. & Comput. Eng., Indian Inst. of Technol., Roorkee
fYear
2008
fDate
12-14 Dec. 2008
Firstpage
1
Lastpage
7
Abstract
DDOS attacks generate flooding traffic from multiple sources towards selected nodes and cause obstruction in flow of legitimate information within a network. If the victim node is a server in DMZ requiring fast information processing, the entire network operation stops. We use various lines of honeypot based defence against such attacks. The first line of defence detects the presence of attacks and tags attack flows in real time. The work in this paper concentrates on the next line of defence, where a model for autonomous dynamic honeypot routing has been proposed in response to identified attack flows. We propose the automatic generation of adequate server nodes to service client requests and honeypots to interact with attackers in contained manner. The judicious mixture of servers and honeypots in DMZ at different time intervals provide stable network functionality even in the attacked network. We validate the effectiveness of the approach with modelling on Internet type topology and simulation in ns-2 on a Linux platform.
Keywords
Internet; security of data; telecommunication network routing; telecommunication security; telecommunication traffic; DMZ; Internet type topology; autonomous dynamic honeypot routing; distributed denial of service attacks; flooding traffic; information processing; server nodes; Computer crime; Computer networks; Entropy; Network servers; Protection; Routing; Telecommunication traffic; Testing; Web and internet services; Web server; Autonomous; Distributed Denial of Service; Dynamic Honeypot; Mitigation; Security;
fLanguage
English
Publisher
ieee
Conference_Titel
Networks, 2008. ICON 2008. 16th IEEE International Conference on
Conference_Location
New Delhi
ISSN
1556-6463
Print_ISBN
978-1-4244-3805-1
Type
conf
DOI
10.1109/ICON.2008.4772623
Filename
4772623
Link To Document