Detection of DDoS and IDS Evasion Attacks in a High-Speed Networks Environment

被引:0
|
作者
Oh, Jin-Tae [1 ]
Park, Sang-Kil [1 ]
Jang, Jong-Soo [1 ]
Jeon, Yong-Hee [2 ]
机构
[1] ETRI, Informat Secur Res Div, Appl Secur Grp, Daejeon, South Korea
[2] Catholic Univ Daegu, Sch Comp & Informat Commun Engn, Gyongsan, Gyeongbuk, South Korea
关键词
IDS(Intrusion Detection System); DoS(Denial of Service) attack; Bandwidth Control; IDS evasion attack;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
BcN(Broadband convergence Networks) is being deployed in order to support a variety of network applications such as E-Commerce, DMB(Digital Multimedia Broadcasting), Home Network, VoIP(Voice over IP), and other services. As network bandwidth is growing rapidly and services are converged, the opportunity and severity of network intrusions are growing as well. This paper presents a novel Intrusion Detection System (IDS) architecture named 'Security Gateway System (SGS)' designed to perform intrusion detection and prevention on highspeed network links. Among several other features in the system, we focus on the detection of DDoS(Distributed Denial of Service) and IDS evasion attacks. We implemented both the mechanisms for handling the bandwidth consuming attack and the detection engine against IDS evasion attack in FPGA(Field Programmable Gate Array). We present some experimental results in a gigabit test bed. The results show that the real-time detection against both attacks is possible with 2 gigabits throughput in each security board.
引用
收藏
页码:124 / 131
页数:8
相关论文
共 50 条
  • [1] Accurate and Fast Detection of DDoS Attacks in High-Speed Network with Asymmetric Routing
    Wu, Hua
    Chen, Tingzheng
    Shao, Ziling
    Cheng, Guang
    Hu, Xiaoyan
    [J]. 2021 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2021,
  • [2] An Efficient IDS Framework for DDoS Attacks in SDN Environment
    Varghese, Josy Elsa
    Muniyal, Balachandra
    [J]. IEEE ACCESS, 2021, 9 : 69680 - 69699
  • [3] General IDS Acceleration for High-Speed Networks
    Kucera, Jan
    Kekely, Lukas
    Piecek, Adam
    Korenek, Jan
    [J]. 2018 IEEE 36TH INTERNATIONAL CONFERENCE ON COMPUTER DESIGN (ICCD), 2018, : 366 - 373
  • [4] Classifying DDoS packets in high-speed networks
    Xiang, Yang
    Zhou, Wanlei
    [J]. INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2006, 6 (2B): : 107 - 115
  • [5] ALPi: A DDoS defense system for high-speed networks
    Ayres, Paulo E.
    Sun, Huizhong
    Chao, H. Jonathan
    Lau, Wing Cheong
    [J]. IEEE JOURNAL ON SELECTED AREAS IN COMMUNICATIONS, 2006, 24 (10) : 1864 - 1876
  • [6] Intelligent DDoS packet filtering in high-speed networks
    Xiang, Y
    Zhou, WL
    [J]. PARALLEL AND DISTRIBUTED PROCESSING AND APPLICATIONS, 2005, 3758 : 395 - 406
  • [7] High-Speed Network DDoS Attack Detection: A Survey
    Haseeb-ur-rehman, Rana M. Abdul
    Aman, Azana Hafizah Mohd
    Hasan, Mohammad Kamrul
    Ariffin, Khairul Akram Zainol
    Namoun, Abdallah
    Tufail, Ali
    Kim, Ki-Hyung
    [J]. SENSORS, 2023, 23 (15)
  • [8] An AI Based IDS Framework For Detecting DDoS Attacks In Cloud Environment
    Varma, S. Asha
    Reddy, K. Ganesh
    [J]. INFORMATION SECURITY JOURNAL, 2023,
  • [9] AF-FDS: An Accurate, Fast, and Fine-Grained Detection Scheme for DDoS Attacks in High-Speed Networks With Asymmetric Routing
    Shao, Ziling
    Chen, Tingzheng
    Cheng, Guang
    Hu, Xiaoyan
    Li, Weina
    Wu, Hua
    [J]. IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2023, 20 (04): : 4964 - 4981
  • [10] Detection of DDOS Attacks in Cloud Computing Environment
    Hamdani, Farhaan Noor
    Siddiqui, Farheen
    [J]. PROCEEDINGS OF THE 2019 INTERNATIONAL CONFERENCE ON INTELLIGENT COMPUTING AND CONTROL SYSTEMS (ICCS), 2019, : 83 - 87