首页> 外文会议>IEEE International Conference on Recent Trends in Electronics, Information and Communication Technology >Anomaly based Mitigation of Volumetric DDoS Attack Using Client Puzzle as Proof-of-Work
【24h】

Anomaly based Mitigation of Volumetric DDoS Attack Using Client Puzzle as Proof-of-Work

机译:使用客户端难题作为工作量证明的基于体积的DDoS攻击的异常缓解

获取原文
获取外文期刊封面目录资料

摘要

Increasing use of Internet has made its users vulnerable to various types of attacks like Distributed Denial of Service (DDoS) attack which makes the resources unavailable to the benign user. Many mechanisms exist against DDoS attack for its detection, prevention, response and mitigation. One such technique is use of client puzzle which has main motive to prevent the attackers from flooding the Internet Service Provider (ISP) network by checking the incoming packets for the sending rights in the form of client puzzle solution. In this paper, we present a combination of anomaly and volume based approaches to safeguard the victim network from DDoS attack by checking the sender for having sending rights which are granted against a challenge puzzle generated by client puzzle module and diverting the attack traffic to dynamic provisioning module when the flooding traffic is becoming cumbersome to be handled by the victim. This technique is dynamic in nature which is activated on the basis of volume of traffic being flooded towards the victim. NS2 network simulator is used to simulate the proposed approach. The proposed approach limits various limitations of existing approaches, i.e. it reduces the collateral damage by distinguishing packets having Proof of Work (PoW). The simulation results depict high malicious packet drop rate and less benign packet drop rate.
机译:越来越多的Internet使用使其用户容易受到各种类型的攻击,例如分布式拒绝服务(DDoS)攻击,这会使良性用户无法使用资源。存在许多针对DDoS攻击的机制,以对其进行检测,预防,响应和缓解。一种这样的技术是客户端难题的使用,其主要目的是通过以客户端难题解决方案的形式检查传入数据包的发送权限来防止攻击者淹没Internet服务提供商(ISP)网络。在本文中,我们提出了一种基于异常和基于数量的方法相结合的方法,通过检查发件人是否具有针对客户端难题模块生成的挑战难题所授予的发送权,并将攻击流量转移到动态预配置中,从而保护受害者网络免受DDoS攻击。当洪泛流量变得繁琐而无法由受害者处理时,该模块可以提供帮助。这种技术本质上是动态的,它是根据向受害者泛滥的流量来激活的。 NS2网络模拟器用于模拟所提出的方法。所提出的方法限制了现有方法的各种局限性,即,通过区分具有工作量证明(PoW)的分组来减少附带损害。仿真结果表明恶意数据包丢弃率较高,而良性数据包丢弃率较低。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号