A novel marking-based detection and filtering scheme against distributed denial of service attack

The Denial of Service (DoS) attack, including Distributed Denial of Service (DDoS) Attack, has become one of the major threats to the Internet today. The victim's resources are exhausted so that its services are disrupted under the DoS attack. Spoofed packets, in which the source IP addresses a...

Full description

Bibliographic Details
Main Author: Chen, Yao
Format: Others
Language:en
Published: University of Ottawa (Canada) 2013
Subjects:
Online Access:http://hdl.handle.net/10393/27117
http://dx.doi.org/10.20381/ruor-18547
id ndltd-uottawa.ca-oai-ruor.uottawa.ca-10393-27117
record_format oai_dc
spelling ndltd-uottawa.ca-oai-ruor.uottawa.ca-10393-271172018-01-05T19:07:24Z A novel marking-based detection and filtering scheme against distributed denial of service attack Chen, Yao Computer Science. The Denial of Service (DoS) attack, including Distributed Denial of Service (DDoS) Attack, has become one of the major threats to the Internet today. The victim's resources are exhausted so that its services are disrupted under the DoS attack. Spoofed packets, in which the source IP addresses are forged, are usually used by attackers to implement the attacks or disguise their actual locations. In this thesis, we investigate DoS attack, analyze some existing defense mechanisms, and compare their strengths and weaknesses. Then, we present a novel Marking-based DDoS Attack Detection and Filtering (MDADF) scheme. The MDADF system can distinguish and filter out spoofed IP packets by maintaining a record of the legitimate users and their markings. The system also functions as a DDoS attack detector. We evaluate the performance of this under various conditions in a simulated environment. The results demonstrate that the system is effective in defending against massive DDoS attacks, even when only 20% of the routers on the Internet participate in the marking process. The system is specially effective against IP-spoofed attacks, which are the most difficult to control, although it works well even under randomized attacks. Moreover, the system detects the occurrence of an attack quite quickly and precisely. 2013-11-07T18:13:02Z 2013-11-07T18:13:02Z 2006 2006 Thesis Source: Masters Abstracts International, Volume: 44-06, page: 2836. http://hdl.handle.net/10393/27117 http://dx.doi.org/10.20381/ruor-18547 en 104 p. University of Ottawa (Canada)
collection NDLTD
language en
format Others
sources NDLTD
topic Computer Science.
spellingShingle Computer Science.
Chen, Yao
A novel marking-based detection and filtering scheme against distributed denial of service attack
description The Denial of Service (DoS) attack, including Distributed Denial of Service (DDoS) Attack, has become one of the major threats to the Internet today. The victim's resources are exhausted so that its services are disrupted under the DoS attack. Spoofed packets, in which the source IP addresses are forged, are usually used by attackers to implement the attacks or disguise their actual locations. In this thesis, we investigate DoS attack, analyze some existing defense mechanisms, and compare their strengths and weaknesses. Then, we present a novel Marking-based DDoS Attack Detection and Filtering (MDADF) scheme. The MDADF system can distinguish and filter out spoofed IP packets by maintaining a record of the legitimate users and their markings. The system also functions as a DDoS attack detector. We evaluate the performance of this under various conditions in a simulated environment. The results demonstrate that the system is effective in defending against massive DDoS attacks, even when only 20% of the routers on the Internet participate in the marking process. The system is specially effective against IP-spoofed attacks, which are the most difficult to control, although it works well even under randomized attacks. Moreover, the system detects the occurrence of an attack quite quickly and precisely.
author Chen, Yao
author_facet Chen, Yao
author_sort Chen, Yao
title A novel marking-based detection and filtering scheme against distributed denial of service attack
title_short A novel marking-based detection and filtering scheme against distributed denial of service attack
title_full A novel marking-based detection and filtering scheme against distributed denial of service attack
title_fullStr A novel marking-based detection and filtering scheme against distributed denial of service attack
title_full_unstemmed A novel marking-based detection and filtering scheme against distributed denial of service attack
title_sort novel marking-based detection and filtering scheme against distributed denial of service attack
publisher University of Ottawa (Canada)
publishDate 2013
url http://hdl.handle.net/10393/27117
http://dx.doi.org/10.20381/ruor-18547
work_keys_str_mv AT chenyao anovelmarkingbaseddetectionandfilteringschemeagainstdistributeddenialofserviceattack
AT chenyao novelmarkingbaseddetectionandfilteringschemeagainstdistributeddenialofserviceattack
_version_ 1718602171365195776