• DocumentCode
    3075050
  • Title

    A Payload driven Security model for flooding attacks in Active networks

  • Author

    Jayashree, P. ; Easwarakumar, K.S. ; Radhakrishnan, D. ; Lakshmanan, N. ; Dinakaran, P.

  • Author_Institution
    Dept. of Inf. Technol., Anna Univ., Chennai
  • fYear
    2009
  • fDate
    6-7 March 2009
  • Firstpage
    934
  • Lastpage
    939
  • Abstract
    In today´s fast growing Internet world, the number of distributed denial of service attacks (DDoS) is increasing at an alarming rate. Evading these attacks has created a lot of attention from researchers. A number of monitoring and filtering devices have been developed to verify the authenticity of the packets based on the packet payload data in intrusion detection systems (IDS). However, the methods used for IDS cannot be deployed in DDoS filters since in DDoS attacks, a lot of packets arrive in a short span of time and deriving packet payload patterns become cumbersome with these IDS algorithms. This paper presents a three-level mechanism to distinguish attack packets from legitimate ones by scanning the payload of the packet. Packet patterns are derived by using the eigen vector concept and the obtained patterns are compared using an optimal string matching algorithm. This three-level filter was tested in the ANTS active network tool kit with the 1999 DARPA IDS dataset as the back end. Results validate the proposed scheme´s efficiency and the time complexity of the filter proposed is smaller than IDS payload scanning methodologies.
  • Keywords
    Internet; eigenvalues and eigenfunctions; message authentication; string matching; telecommunication security; DDoS attack; Internet; active network; distributed denial-of-service attack; eigen vector; flooding attack; intrusion detection system; optimal string matching algorithm; packet authenticity; packet payload data; payload driven security model; Computer crime; Computer networks; Computer security; Detectors; Filtering; Filters; Intrusion detection; Payloads; Telecommunication traffic; Traffic control; ANTS; Anomaly detection; Distributed Denial of Service attack; Eigen Vector; Payload modeling; String matching;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Advance Computing Conference, 2009. IACC 2009. IEEE International
  • Conference_Location
    Patiala
  • Print_ISBN
    978-1-4244-2927-1
  • Electronic_ISBN
    978-1-4244-2928-8
  • Type

    conf

  • DOI
    10.1109/IADCC.2009.4809140
  • Filename
    4809140