Title :
DDoS Attack detection method and mitigation using pattern of the flow
Author :
Sanmorino, Ahmad ; Yazid, Setiadi
Author_Institution :
Fac. of Comput. Sci., Univ. Indonesia, Depok, Indonesia
Abstract :
Distributed denial-of-service attack (DDoS Attack) is one of the types of attacks that use multiple hosts as attacker against a system. There is a difference between Distributed Denial-of-Service (DDoS Attack) and Denial-of-Service (DoS Attack). DDoS attacks are distributed, meaning spread using multiple hosts, while the DoS attack is one-on-one. DoS attacks requires a powerful host, either from the resource or operating system used to carry out the attack. In this study, we discuss how to handle DDoS attacks in the form of detection method based on the pattern of flow entries and handling mechanism using layered firewall. Tests carried out using three scenario that is simulations on normal network environment, unsecured network, and secure network. Then, we analyze the simulations result that has been done. The method used successfully filtering incoming packet, by dropped packets from the attacker when DDoS attack happen, while still be able to receive packets from legitimate hosts.
Keywords :
computer network security; operating systems (computers); pattern recognition; DDoS attack detection method; DDoS attack mitigation; distributed denial-of-service attack; flow pattern; operating system; Computer crime; Computer hacking; Computers; Floods; IP networks; Servers; distributed denial-of-service attack; simulation;
Conference_Titel :
Information and Communication Technology (ICoICT), 2013 International Conference of
Conference_Location :
Bandung
Print_ISBN :
978-1-4673-4990-1
DOI :
10.1109/ICoICT.2013.6574541