Dual-Level Attack Detection, Characterization and Response for Networks Under DDoS Attacks

  • Authors:
  • Anjali Sardana;Ramesh C. Joshi

  • Affiliations:
  • Indian Institute of Technology Roorkee, India;Indian Institute of Technology Roorkee, India

  • Venue:
  • International Journal of Mobile Computing and Multimedia Communications
  • Year:
  • 2011

Quantified Score

Hi-index 0.00

Visualization

Abstract

DDoS attacks aim to deny legitimate users of the services. In this paper, the authors introduce dual-level attack detection D-LAD scheme for defending against the DDoS attacks. At higher and coarse level, the macroscopic level detectors MaLAD attempt to detect congestion inducing attacks which cause apparent slowdown in network functionality. At lower and fine level, the microscopic level detectors MiLAD detect sophisticated attacks that cause network performance to degrade gracefully and stealth attacks that remain undetected in transit domain and do not impact the victim. The response mechanism then redirects the suspicious traffic of anomalous flows to honeypot trap for further evaluation. It selectively drops the attack packets and minimizes collateral damage in addressing the DDoS problem. Results demonstrate that this scheme is very effective and provides the quite demanded solution to the DDoS problem.