Autonomous Agent for DDoS Attack Detection and Defense in an Experimental Testbed
نویسندگان
چکیده
Distributed Denial of Service (DDoS) attacks impinge on the availability of critical resources in the Internet domain. The objective of this paper is to develop an autonomous agent based DDoS defense in real time without human intervention. A mathematical model based on Lanchester law has been designed to examine the strength of DDoS attack and defense group. Once attack strength is formulated efficient defense mechanism is deployed at the victim to block malicious flows. The proposed framework is validated in an experimental testbed with geographically distributed testbed nodes. From the experimental results, the strength of attack group is observed as 49%. The defense strength of Hop Count Filtering mechanism is obtained as 31.3% whereas the proposed Hybrid Model defense effectiveness is computed as 48.7%. Also, Adaptive Bandwidth Management (ABM) using fuzzy inference system provides sustainable bandwidth to legitimate users by providing low bandwidth share for attackers. The proposed autonomous agent based model defends against DDoS attack in various aspects like prevention of IP spoofing, effective bandwidth management, improvement of Quality of Service provisioning, availability of services to legitimate clients and protecting critical infrastructure points. The defense mechanism paves way to Critical Information Infrastructure Protection.
منابع مشابه
Design of an Autonomous Anti-DDoS (A2D2) Network
The threat of DDoS attack are mainly directed at home and SOHO network that lacks the incentive, expertise, and financial means to defend themselves. This paper proposes an Autonomous Anti-DDoS Network Design (A2D2) that integrates and improves existing technologies. A2D2 enables SOHO networks to take control of their own defense within their own boundary. Testbed results show that A2D2 is effe...
متن کاملDistributed Change-Point Detection of DDoS Attacks: Experimental Results on DETER Testbed
It is highly desired to detect the DDoS flooding attacks at an early stage in order to launch effective countermeasures timely. We have developed a distributed change-point detection scheme to detect flooding type DDoS attacks over multiple network domains. The approach is to monitor the spatiotemporal pattern of the attack traffic. We have simulated the new defense system on the DETER testbed....
متن کاملF-STONE: A Fast Real-Time DDOS Attack Detection Method Using an Improved Historical Memory Management
Distributed Denial of Service (DDoS) is a common attack in recent years that can deplete the bandwidth of victim nodes by flooding packets. Based on the type and quantity of traffic used for the attack and the exploited vulnerability of the target, DDoS attacks are grouped into three categories as Volumetric attacks, Protocol attacks and Application attacks. The volumetric attack, which the pro...
متن کاملNeural Network Based Protection of Software Defined Network Controller against Distributed Denial of Service Attacks
Software Defined Network (SDN) is a new architecture for network management and its main concept is centralizing network management in the network control level that has an overview of the network and determines the forwarding rules for switches and routers (the data level). Although this centralized control is the main advantage of SDN, it is also a single point of failure. If this main contro...
متن کاملA Distributed Denial of Service Testbed
The Denial of Service Testing Framework (dosTF) being developed as part of the joint India-Australia research project for ‘Protecting Critical Infrastructure from Denial of Service Attacks’ allows for the construction, monitoring and management of emulated Distributed Denial of Service attacks using modest hardware resources. The purpose of the testbed is to study the effectiveness of different...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2014