Predicting the Impact of Denial of Service Attacks

نویسنده

  • Cyrill Bannwart
چکیده

Denial-of-service (DoS) attacks have become a major threat to current systems and networks in the Internet. Yet the existing infrastructure is rarely tested for potential damage caused by (D)DoS attacks because no method exist to audit a productive system without flooding and thus risking system outages and resulting losses. Having a method that does (D)DoS attack auditing without requiring the observation of the system under massive load is however crucial when testing critical infrastructure in a productive environment. We present a novel auditing method to externally assess and predict the impact of (D)DoS attacks on web servers based on low strength (D)DoS attack measurements. The developed method reduces the required probe traffic and relies on pre-established (D)DoS attack models to infer the impact of similar attacks at a stronger attack strength. To model the impact of (D)DoS attacks a multitude of server-internal as well as server-external metrics has been analyzed to identify those metrics, that characterize the state of the server and can be measured externally without requiring privileged access to the system and its network. The presented auditing method is evaluated for multiple current and common (D)DoS attacks using extensive measurements, analyzing the influence caused by variations in the intermediate network as well as in software and hardware on the web server. Calculating the error rate between prediction and actual measurements the accuracy of the method is verified resulting in an expected error rate of 10% at a limited attack strength of 30% of the strength causing a DoS. Additionally as a prototype an audit framework was developed, which implements the presented auditing method and allows anyone to asses the impact of a (D)DoS attack on a web server in the Internet.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

HF-Blocker: Detection of Distributed Denial of Service Attacks Based On Botnets

Abstract—Today, botnets have become a serious threat to enterprise networks. By creation of network of bots, they launch several attacks, distributed denial of service attacks (DDoS) on networks is a sample of such attacks. Such attacks with the occupation of system resources, have proven to be an effective method of denying network services. Botnets that launch HTTP packet flood attacks agains...

متن کامل

Detecting Denial of Service Message Flooding Attacks in SIP based Services

Increasing the popularity of SIP based services (VoIP, IPTV, IMS infrastructure) lead to concerns about its ‎security. The main signaling protocol of next generation networks and VoIP systems is Session Initiation Protocol ‎‎(SIP). Inherent vulnerabilities of SIP, misconfiguration of its related components and also its implementation ‎deficiencies cause some security concerns in SIP based infra...

متن کامل

Neural Network Based Protection of Software Defined Network Controller against Distributed Denial of Service Attacks

Software Defined Network (SDN) is a new architecture for network management and its main concept is centralizing network management in the network control level that has an overview of the network and determines the forwarding rules for switches and routers (the data level). Although this centralized control is the main advantage of SDN, it is also a single point of failure. If this main contro...

متن کامل

Moving dispersion method for statistical anomaly detection in intrusion detection systems

A unified method for statistical anomaly detection in intrusion detection systems is theoretically introduced. It is based on estimating a dispersion measure of numerical or symbolic data on successive moving windows in time and finding the times when a relative change of the dispersion measure is significant. Appropriate dispersion measures, relative differences, moving windows, as well as tec...

متن کامل

The Impact of Application Layer Denial of Service Attacks

A recent escalation of application layer Denial of Service attacks (DoS) on the Internet has quickly shifted the focus of the research community from traditional network-based denial of service. As a result, new varieties of attacks were explored: slow-rate and low-rate application layer DoS attacks. In this chapter, after a brief introduction of application layer DoS attacks, we discuss the ch...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2012