A Measure for Assessing the Adequacy of DDOS Defenses

نویسندگان

  • Jordan Shropshire
  • Jack A. Gowan
چکیده

This research proposes a measure for assessing the adequacy of DDOS detection systems. DDOS attacks pose serious threats to businesses around the globe. The best defense incorporates a plurality of detection methods. To increase the likelihood that malicious traffic can be effectively identified, multiple detection tests should be used. However, the complexity and quantity of contemporary tests makes selection difficult. This research proposes a metric developed to assist in making such determinations. The measure was developed in three stages: first, a review of contemporary detection algorithms was conducted in order to identify specific tactics. Second, the results were clustered into logical groupings which were improved over multiple iterations. Finally, a Delphi group provided recommendations and feedback via two rounds of revision. The result is a formative measure consisting of 28 separate tests organized into 10 categories. It can be used to assess in-place defenses or guide development of new detection systems.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Scalable Cloud Defenses for Detection, Analysis and Mitigation of DDoS Attacks

Distributed denial of service (DDoS) is considered as one of the most serious threats to emerging cloud computing infrastructures. It aims at denying access to the cloud infrastructure by making it unavailable to its users. This can cause important economic and organizational damage depending on the type of applications running on the cloud that have become unavailable. This paper proposes an e...

متن کامل

Characterization of defense mechanisms against distributed denial of service attacks

We propose a characterization of distributed denial-of-service (DDOS) defenses where reaction points are network-based and attack responses are active. The purpose is to provide a framework for comparing the performance and deployment of DDOS defenses. We identify the characteristics in attack detection algorithms and attack responses by reviewing defenses that have appeared in the literature. ...

متن کامل

The Economic Incentives Of Providing Network Security Services On The Internet Infrastructure

Distributed denial-of-service (DDOS) attacks have emerged as a prevalent way to compromise the availability of networks/servers, which imposed financial losses for e-commerce businesses. Many defenses that mitigate the effect of ongoing DDOS attacks have been proposed. However, none of the defenses have been widely deployed on the Internet infrastructure at this point because of a lack of under...

متن کامل

Numerical Evaluation of Cloud-Side Shuffling Defenses against DDoS Attacks on Proxied Multiserver Systems

We consider a cloud based multiserver system, that may be cloud based, consisting of a set of replica application servers behind a set of proxy (indirection) servers which interact directly with clients over the Internet. We address cloud-side proactive and reactive defenses to combat DDoS attacks that may target this system. DDoS attacks are endemic with some notable attacks occurring just thi...

متن کامل

Assessing the factors affecting liquidity by focusing on the capital adequacy ratio of the banking network and its asymmetric effects

Liquidity , as the most important variable of the money market , has a significant role in economic performance from various aspects and therefore it is important to identify the factors affecting liquidity. Considering that one of the channels to increase liquidity is loans paid by the banking network and the effective role of capital adequacy ratio in the payment of bank loans, in the present...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2013