Adaptive Response System for Distributed Denial-of-Service Attacks

被引:5
|
作者
Thing, Vrizlynn L. L.
Sloman, Morris
Dulay, Naranker
机构
关键词
Distributed Denial of Service; Adaptive Response System;
D O I
10.1109/INM.2009.5188887
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
This dissertation presents a Distributed denial-of-service Adaptive ResponsE (DARE) system, capable of executing appropriate detection and mitigation responses automatically and adaptively according to the attacks. It supports easy integration of distributed modules for both signature-based and anomaly-based detection. Additionally, the innovative design of DARE's individual components takes into consideration the strengths and weaknesses of existing defence mechanisms, and the characteristics and possible future mutations of DDoS attacks. The distributed components work together interactively to adapt detection and response according to the attack types. Experiments on DARE show that the attack detection and mitigation were successfully completed within seconds, with about 60% to 86% of the attack traffic being dropped, while availability for legitimate and new legitimate requests was maintained. DARE is able to detect and trigger appropriate responses in accordance to the attacks being launched with high accuracy, effectiveness and efficiency. The dissertation is available at http://pubs.doc.ic.ac.ukNrizlynnThing-PhD-Thesis-2008/VrizlynnThing-PhD-Thesis-2008.pdf.
引用
下载
收藏
页码:809 / 814
页数:6
相关论文
共 50 条
  • [31] Denial-of-service attacks and countermeasures on BitTorrent
    Lehmann, Matheus Brenner
    Santos, Flavio Roberto
    Gaspary, Luciano Paschoal
    Barcellos, Marinho Pilla
    COMPUTER NETWORKS, 2012, 56 (15) : 3479 - 3498
  • [32] Preventing Distributed Denial-of-Service Flooding Attacks With Dynamic Path Identifiers
    Luo, Hongbin
    Chen, Zhe
    Li, Jiawei
    Vasilakos, Athanasios V.
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2017, 12 (08) : 1801 - 1815
  • [33] Detecting distributed denial-of-service attacks using Kolmogorov complexity metrics
    Kulkarni, Amit
    Bush, Stephen
    JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2006, 14 (01) : 69 - 80
  • [34] PFS: Probabilistic Filter Scheduling Against Distributed Denial-of-Service Attacks
    Seo, Dongwon
    Lee, Heejo
    Perrig, Adrian
    2011 IEEE 36TH CONFERENCE ON LOCAL COMPUTER NETWORKS (LCN), 2011, : 9 - 17
  • [35] Detecting Distributed Denial-of-Service Attacks Using Kolmogorov Complexity Metrics
    Amit Kulkarni
    Stephen Bush
    Journal of Network and Systems Management, 2006, 14 : 69 - 80
  • [36] Optimizing the pulsing denial-of-service attacks
    Luo, XP
    Chang, RKC
    2005 INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS, PROCEEDINGS, 2005, : 582 - 591
  • [37] Denial-of-service attacks rip the Internet
    Garber, L
    COMPUTER, 2000, 33 (04) : 12 - 17
  • [38] A technique to make a path table for blocking Distributed Denial-of-Service attacks
    Eun, JeeSook
    Jung, Heeyoung
    2015 9TH INTERNATIONAL CONFERENCE ON FUTURE GENERATION COMMUNICATION AND NETWORKING (FGCN), 2015, : 13 - 16
  • [39] A divide-and-conquer strategy for thwarting distributed denial-of-service attacks
    Chen, Ruiliang
    Park, Jung-Min
    Marchany, Randolph
    IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2007, 18 (05) : 577 - 588
  • [40] Characterizing flash events and distributed denial-of-service attacks: an empirical investigation
    Bhandari, Abhinav
    Sangal, Amrit Lal
    Kumar, Krishan
    SECURITY AND COMMUNICATION NETWORKS, 2016, 9 (13) : 2222 - 2239