MECPASS: Distributed Denial of Service Defense Architecture for Mobile Networks

被引:15
|
作者
Van Linh Nguyen [1 ]
Lin, Po-Ching [1 ]
Hwang, Ren-Hung [1 ]
机构
[1] Natl Chung Cheng Univ, Chiayi, Taiwan
来源
IEEE NETWORK | 2018年 / 32卷 / 01期
关键词
ATTACKS;
D O I
10.1109/MNET.2018.1700140
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Distributed denial of service is one of the most critical threats to the availability of Internet services. A botnet with only 0.01 percent of the 50 billion connected devices in the Internet of Things is sufficient to launch a massive DDoS flooding attack that could exhaust resources and interrupt any target. However, the mobility of user equipment and the distinctive characteristics of traffic behavior in mobile networks also limit the detection capabilities of traditional anti-DDoS techniques. In this article, we present a novel collaborative DDoS defense architecture called MECPASS to mitigate the attack traffic from mobile devices. Our design involves two filtering hierarchies. First, filters at edge computing servers (i.e., local nodes) seek to prevent spoofing attacks and anomalous traffic near sources as much as possible. Second, global analyzers located at cloud servers (i.e., central nodes) classify the traffic of the entire monitored network and unveil suspicious behaviors by periodically aggregating data from the local nodes. We have explored the effectiveness of our system on various types of application-layer DDoS attacks in the context of web servers. The simulation results show that MECPASS can effectively defend and clean an Internet service provider core network from the junk traffic of compromised UEs, while maintaining the false-positive rate of its detection engine at less than 1 percent.
引用
收藏
页码:118 / 124
页数:7
相关论文
共 50 条
  • [31] Barycentric Coordinate-Based Distributed Localization for Mobile Sensor Networks Under Denial-of-Service Attacks
    Shi, Lei
    Shi, Huaguang
    Ma, Zhuangzhuang
    Yan, Shuaiming
    Zhou, Yi
    [J]. IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2024, 20 (05) : 8019 - 8030
  • [32] Efficient and low-cost defense against distributed denial-of-service attacks in SDN-based networks
    Wang, You-Chiun
    Wang, Yi-Chuan
    [J]. INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2020, 33 (14)
  • [33] Distributed denial of service attacks
    Lau, F
    Rubin, SH
    Smith, MH
    Trajkovic, L
    [J]. SMC 2000 CONFERENCE PROCEEDINGS: 2000 IEEE INTERNATIONAL CONFERENCE ON SYSTEMS, MAN & CYBERNETICS, VOL 1-5, 2000, : 2275 - 2280
  • [34] A Review on Distributed Denial of Service
    Ali, Usman
    ul Hassan, Abu
    Malik, Muhammad Sheraz Arshad
    Hashmi, Syed Kashif
    Aslam, Bushra
    Ayub, Basit
    [J]. INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2018, 18 (08): : 139 - 143
  • [35] A Distributed Denial of Service Testbed
    Schmidt, Desmond
    Suriadi, Suriadi
    Tickle, Alan
    Clark, Andrew
    Mohay, George
    Ahmed, Ejaz
    Mackie, James
    [J]. WHAT KIND OF INFORMATION SOCIETY? GOVERNANCE, VIRTUALITY, SURVEILLANCE, SUSTAINABILITY, RESILIENCE, 2010, 328 : 338 - 349
  • [36] Analysis of the effects of distributed denial-of-service attacks on MPLS networks
    Genge, Bela
    Siaterlis, Christos
    [J]. INTERNATIONAL JOURNAL OF CRITICAL INFRASTRUCTURE PROTECTION, 2013, 6 (02) : 87 - 95
  • [37] Comprehensive review on distributed denial of service attacks in wireless sensor networks
    Subramani, Shalini
    Selvi, M.
    [J]. INTERNATIONAL JOURNAL OF INFORMATION AND COMPUTER SECURITY, 2023, 20 (3-4) : 414 - 438
  • [38] An approach to detecting distributed denial of service attacks in software defined networks
    Sangodoyin, Abimbola
    Modu, Babagana
    Awan, Irfan
    Disso, Jules Pagna
    [J]. 2018 IEEE 6TH INTERNATIONAL CONFERENCE ON FUTURE INTERNET OF THINGS AND CLOUD (FICLOUD 2018), 2018, : 436 - 443
  • [39] High performance distributed denial-of-service resilient web cluster architecture
    Ranjan, Supranamaya
    Knightly, Edward
    [J]. 2008 IEEE NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM, VOLS 1 AND 2, 2008, : 1019 - +
  • [40] Multilevel Modeling of Distributed Denial of Service Attacks in Wireless Sensor Networks
    Mazur, Katarzyna
    Ksiezopolski, Bogdan
    Nielek, Radoslaw
    [J]. JOURNAL OF SENSORS, 2016, 2016