• DocumentCode
    628061
  • Title

    DDoS Attack detection method and mitigation using pattern of the flow

  • Author

    Sanmorino, Ahmad ; Yazid, Setiadi

  • Author_Institution
    Fac. of Comput. Sci., Univ. Indonesia, Depok, Indonesia
  • fYear
    2013
  • fDate
    20-22 March 2013
  • Firstpage
    12
  • Lastpage
    16
  • Abstract
    Distributed denial-of-service attack (DDoS Attack) is one of the types of attacks that use multiple hosts as attacker against a system. There is a difference between Distributed Denial-of-Service (DDoS Attack) and Denial-of-Service (DoS Attack). DDoS attacks are distributed, meaning spread using multiple hosts, while the DoS attack is one-on-one. DoS attacks requires a powerful host, either from the resource or operating system used to carry out the attack. In this study, we discuss how to handle DDoS attacks in the form of detection method based on the pattern of flow entries and handling mechanism using layered firewall. Tests carried out using three scenario that is simulations on normal network environment, unsecured network, and secure network. Then, we analyze the simulations result that has been done. The method used successfully filtering incoming packet, by dropped packets from the attacker when DDoS attack happen, while still be able to receive packets from legitimate hosts.
  • Keywords
    computer network security; operating systems (computers); pattern recognition; DDoS attack detection method; DDoS attack mitigation; distributed denial-of-service attack; flow pattern; operating system; Computer crime; Computer hacking; Computers; Floods; IP networks; Servers; distributed denial-of-service attack; simulation;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information and Communication Technology (ICoICT), 2013 International Conference of
  • Conference_Location
    Bandung
  • Print_ISBN
    978-1-4673-4990-1
  • Type

    conf

  • DOI
    10.1109/ICoICT.2013.6574541
  • Filename
    6574541