Modelling and Simulation of A Defense Strategy to Face Indirect DDoS Flooding Attacks


Abstract:

Distributed Denial of Service (DDoS) flooding attack is one of the most diffused and effective threat against services and applications running over the Internet. Its distributed and cooperative nature makes it complicated to prevent and/or to counteract. StopIt is a robust, filter-based defence mechanism which is able to deal with various types of massive DDoS flooding attacks but which fails when the DDoS is achieved indirectly, i.e. by congestion of a link shared with the victim. This paper introduces an extension of StopIt which makes it able to cooperate with capability-based mechanisms for defeating indirect attacks. The enhanced version of the protocol has been implemented into the ns-3 simulator and its effectiveness has been evaluated under different scenarios.

Año de publicación:

2014

Keywords:

    Fuente:

    scopusscopus

    Tipo de documento:

    Article

    Estado:

    Acceso restringido

    Áreas de conocimiento:

    • Simulación por computadora
    • Ciencias de la computación

    Áreas temáticas:

    • Programación informática, programas, datos, seguridad
    • Ciencia militar
    • Otras ramas de la ingeniería