Adaptive Response System for Distributed Denial-of-Service Attacks

被引:5
|
作者
Thing, Vrizlynn L. L.
Sloman, Morris
Dulay, Naranker
机构
关键词
Distributed Denial of Service; Adaptive Response System;
D O I
10.1109/INM.2009.5188887
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
This dissertation presents a Distributed denial-of-service Adaptive ResponsE (DARE) system, capable of executing appropriate detection and mitigation responses automatically and adaptively according to the attacks. It supports easy integration of distributed modules for both signature-based and anomaly-based detection. Additionally, the innovative design of DARE's individual components takes into consideration the strengths and weaknesses of existing defence mechanisms, and the characteristics and possible future mutations of DDoS attacks. The distributed components work together interactively to adapt detection and response according to the attack types. Experiments on DARE show that the attack detection and mitigation were successfully completed within seconds, with about 60% to 86% of the attack traffic being dropped, while availability for legitimate and new legitimate requests was maintained. DARE is able to detect and trigger appropriate responses in accordance to the attacks being launched with high accuracy, effectiveness and efficiency. The dissertation is available at http://pubs.doc.ic.ac.ukNrizlynnThing-PhD-Thesis-2008/VrizlynnThing-PhD-Thesis-2008.pdf.
引用
下载
收藏
页码:809 / 814
页数:6
相关论文
共 50 条
  • [1] Handling Distributed Denial-of-Service Attacks
    Janczewski, Lech J.
    Information Security Technical Report, 2001, 6 (03): : 37 - 44
  • [2] A Coordinated Detection and Response Scheme for Distributed Denial-of-Service Attacks
    Lam, Ho-Yu
    Li, Chi-Pan
    Chanson, Samuel T.
    Yeung, Dit-Yan
    2006 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, VOLS 1-12, 2006, : 2165 - 2170
  • [3] Using adaptive router throttles against distributed denial-of-service attacks
    Liang, Feng
    Yau, David
    Ruan Jian Xue Bao/Journal of Software, 2002, 13 (07): : 1220 - 1227
  • [4] Distributed defense against distributed denial-of-service attacks
    Shi, W
    Xiang, Y
    Zhou, WL
    DISTRIBUTED AND PARALLEL COMPUTING, 2005, 3719 : 357 - 362
  • [5] Sophistication in distributed denial-of-service attacks on the Internet
    Kumar, VA
    CURRENT SCIENCE, 2004, 87 (07): : 885 - 888
  • [6] Design and Development of Proactive Models for Mitigating Denial-of-Service and Distributed Denial-of-Service Attacks
    Nagesh, H. R.
    Sekaran, K. Chandra
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2007, 7 (07): : 168 - 176
  • [7] On the Move: Evading Distributed Denial-of-Service Attacks
    Stavrou, Angelos
    Fleck, Daniel
    Kolias, Constantinos
    COMPUTER, 2016, 49 (03) : 104 - 107
  • [8] Denial-of-service attacks
    Neumann, PG
    COMMUNICATIONS OF THE ACM, 2000, 43 (04) : 136 - 136
  • [9] APFS: Adaptive Probabilistic Filter Scheduling against distributed denial-of-service attacks
    Seo, Dongwon
    Lee, Heejo
    Perrig, Adrian
    COMPUTERS & SECURITY, 2013, 39 : 366 - 385
  • [10] Harnessing the power of BitTorrent for distributed denial-of-service attacks
    Wu, Lei
    Harrington, Jerome
    Kuwanoe, Corey
    Zou, Cliff C.
    SECURITY AND COMMUNICATION NETWORKS, 2011, 4 (08) : 860 - 870