2012CiiT international journal of networking and communication engineeringRequires access

Entropy Variation Based Detecting DDoS Attack in Large Scale Networks

M. Uthaya Kumar, B. Aysha Banu

Open publisher page 0 citations

Abstract

A distributed denial-of-service (DDoS) attack is an attempt to make a computer resource unavailable to its intended users. A number of IP traceback approaches have been suggested to identify attackers and there are two major methods for IP traceback, the probabilistic packet marking (PPM) and the deterministic packet marking (DPM) Both of these strategies require routers to inject marks into individual packets. The memory less feature occur in the Internet routing mechanisms makes it extremely hard for old mechanisms. So newly introduced effective and efficient IP traceback scheme against DDoS attacks based on entropy variations. In traceback mechanisms identifying the number of zombies in large scale network and all so give the authentication for blocked users. It works as an independent software module with current routing software. When the attack strength is less than seven times of the normal flow packet rate, this efficient IP trace back method cannot succeed at the moment. However, we can detect the attack with the information that we have accumulated so far using Markov-Chain Model for Cyber-Attack Detection. This makes it a feasible and easy to be implemented solution for the current Internet.

About this research paper

What this paper is about

A distributed denial-of-service (DDoS) attack is an attempt to make a computer resource unavailable to its intended users. A number of IP traceback approaches have been suggested to identify attackers and there are two major methods for IP traceback, the probabilistic packet marking (PPM) and the deterministic packet marking (DPM) Both of these strategies require routers to inject marks into individual packets. The memory less feature occur in the Internet routing mechanisms makes it extremely hard for old mechanisms. So newly introduced effective and efficient IP traceback scheme against DDoS attacks based on entropy variations. In traceback mechanisms identifying the number of zombies in large scale network and all so give the authentication for blocked users. It works as an independent software module with current routing software. When the attack strength is less than seven times of the normal flow packet rate, this efficient IP trace back method cannot succeed at the moment. However, we can detect the attack with the information that we have accumulated so far using Markov-Chain Model for Cyber-Attack Detection. This makes it a feasible and easy to be implemented solution for the current Internet.

Why it matters

A significance statement is not available in the OpenAlex record.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

A distributed denial-of-service (DDoS) attack is an attempt to make a computer resource unavailable to its intended users. A number of IP traceback approaches have been suggested to identify attackers and there are two major methods for IP traceback, the probabilistic packet marking (PPM) and the deterministic packet marking (DPM) Both of these strategies require routers to inject marks into individual packets. The memory less feature occur in the Internet routing mechanisms makes it extremely hard for old mechanisms. So newly introduced effective and efficient IP traceback scheme against DDoS attacks based on entropy variations. In traceback mechanisms identifying the number of zombies in large scale network and all so give the authentication for blocked users. It works as an independent software module with current routing software. When the attack strength is less than seven times of the normal flow packet rate, this efficient IP trace back method cannot succeed at the moment. However, we can detect the attack with the information that we have accumulated so far using Markov-Chain Model for Cyber-Attack Detection. This makes it a feasible and easy to be implemented solution for the current Internet.

Key concepts: IP traceback, Denial-of-service attack, Computer science, Packet drop attack, Application layer DDoS attack, Computer network, Network packet, Trinoo

Related papers

Back to paper searchBrowse research topicsOriginal source
Entropy Variation Based Detecting DDoS Attack in Large Scale Networks — Research Paper | ScholarLens