Defence against denial of service in self-aware networks

نویسنده

  • Georgios Loukas
چکیده

Denial of Service (DoS) has become a prevalent threat in today’s networks. Motivated by an impressive variety of reasons and directed against an equally impressive variety of targets, DoS attacks are not as difficult to launch as one would expect. Protection against them is, however, disproportionately difficult. Despite the extensive research in recent years, DoS attacks continue to harm. In our thesis, we start with a historic timeline of DoS incidents to illustrate the variety of types, targets and motives and how DoS attacks evolved during the last 10 years. We then present an overview of the existing proposals on both detection of such attacks and defence against them. Recognising the fact that the networks of the near future will feature self-awareness and online interaction with the users, we investigate the application of existing techniques together with novel techniques that we have designed, on the DoS resilience of Self-Aware Networks (SAN). We introduce a generic framework of DoS protection based on the dropping of probable illegitimate traffic, and we present a mathematical model with which we can measure the impact that both attack and defence have on the performance of a network. The mathematical results are validated with simulation results and experimental measurements in a SAN environment. We then introduce a variation of the generic defence, by using prioritisation and rate-limiting instead of simple dropping. We describe the implementation details and present experimental results. We also present a tool based on our mathematical model, which can recommend the optimal number and distribution of tasks among the defending nodes in a network. Last, we sketch potential future

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Defending against Denial of Service in a Self-Aware Network: A practical approach

In recent years, Denial of Service attacks have evolved into a predominant network security threat. Motivated by an impressive variety of reasons and directed against an equally impressive variety of targets, DoS attacks are not as difficult to launch as one would expect. Protection against them is, however, disproportionately difficult. Recognising the fact that the networks of the near future...

متن کامل

Distributed Defence Against Denial of Service Attacks: A Practical View

In recent years, Denial of Service attacks have evolved into a predominant network security threat. In our previous work, we identified the necessary building blocks for an effective defence mechanism and suggested ways to integrate them. Here, we present the results of this integration on the DoS-resilience of a real networking testbed which runs the Self-Aware CPN routing protocol. The incomi...

متن کامل

HF-Blocker: Detection of Distributed Denial of Service Attacks Based On Botnets

Abstract—Today, botnets have become a serious threat to enterprise networks. By creation of network of bots, they launch several attacks, distributed denial of service attacks (DDoS) on networks is a sample of such attacks. Such attacks with the occupation of system resources, have proven to be an effective method of denying network services. Botnets that launch HTTP packet flood attacks agains...

متن کامل

Period Based Defence Mechanism against Data flooding attacks

There is a wide usage of mobiles anywhere and anytime to access the multimedia data. Thus there will be more oppurtunity for wireless adhoc networks. Because, comparing with the wired networks, wireless networks provides low cost and easy accesibility. But the main disadvantage for Consumer electronic devices were generally operate on limited battery power and therfore are vulnerable to securit...

متن کامل

Cooperative Defence Against DDoS Attacks

Distributed denial of service (DDoS) attacks on the Internet have become an immediate problem. As DDoS streams do not have common characteristics, currently available intrusion detection systems (IDS) cannot detect them accurately. As a result, defend DDoS attacks based on current available IDS will dramatically affect legitimate traffic. In this paper, we propose a distributed approach to defe...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2006