MECPASS: Distributed Denial of Service Defense Architecture for Mobile Networks

被引:15
|
作者
Van Linh Nguyen [1 ]
Lin, Po-Ching [1 ]
Hwang, Ren-Hung [1 ]
机构
[1] Natl Chung Cheng Univ, Chiayi, Taiwan
来源
IEEE NETWORK | 2018年 / 32卷 / 01期
关键词
ATTACKS;
D O I
10.1109/MNET.2018.1700140
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Distributed denial of service is one of the most critical threats to the availability of Internet services. A botnet with only 0.01 percent of the 50 billion connected devices in the Internet of Things is sufficient to launch a massive DDoS flooding attack that could exhaust resources and interrupt any target. However, the mobility of user equipment and the distinctive characteristics of traffic behavior in mobile networks also limit the detection capabilities of traditional anti-DDoS techniques. In this article, we present a novel collaborative DDoS defense architecture called MECPASS to mitigate the attack traffic from mobile devices. Our design involves two filtering hierarchies. First, filters at edge computing servers (i.e., local nodes) seek to prevent spoofing attacks and anomalous traffic near sources as much as possible. Second, global analyzers located at cloud servers (i.e., central nodes) classify the traffic of the entire monitored network and unveil suspicious behaviors by periodically aggregating data from the local nodes. We have explored the effectiveness of our system on various types of application-layer DDoS attacks in the context of web servers. The simulation results show that MECPASS can effectively defend and clean an Internet service provider core network from the junk traffic of compromised UEs, while maintaining the false-positive rate of its detection engine at less than 1 percent.
引用
收藏
页码:118 / 124
页数:7
相关论文
共 50 条
  • [1] On Distributed Denial of Service Current Defense Schemes
    Kotey, Seth Djane
    Tchao, Eric Tutu
    Gadze, James Dzisi
    [J]. TECHNOLOGIES, 2019, 7 (01)
  • [2] Distributed denial of service issues and defense strategies
    Park, J
    [J]. WORLD MULTICONFERENCE ON SYSTEMICS, CYBERNETICS AND INFORMATICS, VOL 1, PROCEEDINGS: INFORMATION SYSTEMS DEVELOPMENT, 2001, : 513 - 516
  • [3] A Defense Mechanism for Distributed Denial of Service Attack in Software-Defined Networks
    Luo, Shibo
    Wu, Jun
    Li, Jianhua
    Pei, Bei
    [J]. 2015 NINTH INTERNATIONAL CONFERENCE ON FRONTIER OF COMPUTER SCIENCE AND TECHNOLOGY FCST 2015, 2015, : 324 - 328
  • [4] A systematic review on distributed denial of service attack defense mechanisms in programmable networks
    Dalmazo, Bruno L.
    Marques, Jonatas A.
    Costa, Lucas R.
    Bonfim, Michel S.
    Carvalho, Ranyelson N.
    da Silva, Anderson S.
    Fernandes, Stenio
    Bordim, Jacir L.
    Alchieri, Eduardo
    Schaeffer-Filho, Alberto
    Paschoal Gaspary, Luciano
    Cordeiro, Weverton
    [J]. INTERNATIONAL JOURNAL OF NETWORK MANAGEMENT, 2021, 31 (06)
  • [5] Distributed defense against distributed denial-of-service attacks
    Shi, W
    Xiang, Y
    Zhou, WL
    [J]. DISTRIBUTED AND PARALLEL COMPUTING, 2005, 3719 : 357 - 362
  • [6] Comparison of Various Passive Distributed Denial of Service Attack in Mobile Adhoc Networks
    Chaba, Yogesh
    Singh, Yudhvir
    Rani, Prabha
    [J]. EHAC'09: PROCEEDINGS OF THE 9TH WSEAS INTERNATIONAL CONFERENCE ON ELECTRONICS, HARDWARE, WIRELESS AND OPTIONAL COMMUNICATIONS, 2010, : 49 - 53
  • [7] Defense and Monitoring Model for Distributed Denial of Service Attacks
    Tariq, Usman
    Malik, Yasir
    Abdulrazak, Bessam
    [J]. ANT 2012 AND MOBIWIS 2012, 2012, 10 : 1052 - 1056
  • [8] RateGuard: A Robust Distributed Denial of Service (DDoS) Defense System
    Sun, Huizhong
    Ngan, Wingchiu
    Chao, H. Jonathan
    [J]. GLOBECOM 2009 - 2009 IEEE GLOBAL TELECOMMUNICATIONS CONFERENCE, VOLS 1-8, 2009, : 2033 - 2040
  • [9] Defense mechanisms against Distributed Denial of Service attacks : A survey
    Manavi, Mousa Taghizadeh
    [J]. COMPUTERS & ELECTRICAL ENGINEERING, 2018, 72 : 26 - 38
  • [10] Characterization of defense mechanisms against distributed denial of service attacks
    Chen, LC
    Longstaff, TA
    Carley, KM
    [J]. COMPUTERS & SECURITY, 2004, 23 (08) : 665 - 678