• DocumentCode
    2743069
  • Title

    Adaptive response system for distributed denial-of-service attacks

  • Author

    Thing, Vrizlynn L L ; Sloman, Morris ; Dulay, Naranker

  • Author_Institution
    Inst. for Infocomm Res., Imperial Coll. London, London, UK
  • fYear
    2009
  • fDate
    1-5 June 2009
  • Firstpage
    809
  • Lastpage
    814
  • Abstract
    This dissertation presents a distributed denial-of-service adaptive response (DARE) system, capable of executing appropriate detection and mitigation responses automatically and adaptively according to the attacks. It supports easy integration of distributed modules for both signature-based and anomaly-based detection. Additionally, the innovative design of DARE´s individual components takes into consideration the strengths and weaknesses of existing defence mechanisms, and the characteristics and possible future mutations of DDoS attacks. The distributed components work together interactively to adapt detection and response according to the attack types. Experiments on DARE show that the attack detection and mitigation were successfully completed within seconds, with about 60% to 86% of the attack traffic being dropped, while availability for legitimate and new legitimate requests was maintained. DARE is able to detect and trigger appropriate responses in accordance to the attacks being launched with high accuracy, effectiveness and efficiency. The dissertation is available at http://pubs.doc.ic.ac.uk/VrizlynnThing-PhD-Thesis-2008/VrizlynnThing-PhD-Thesis-2008.pdf.
  • Keywords
    authorisation; digital signatures; telecommunication traffic; adaptive response system; anomaly-based detection; attack traffic; defence mechanism; distributed denial-of-service attack; signature-based detection; Adaptive systems; Computer crime; Educational institutions; Genetic mutations; IP networks; Network servers; Potential well; Protection; Web and internet services; Web server; Adaptive Response System; Distributed Denial of Service;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Integrated Network Management, 2009. IM '09. IFIP/IEEE International Symposium on
  • Conference_Location
    Long Island, NY
  • Print_ISBN
    978-1-4244-3486-2
  • Electronic_ISBN
    978-1-4244-3487-9
  • Type

    conf

  • DOI
    10.1109/INM.2009.5188887
  • Filename
    5188887