• DocumentCode
    1924467
  • Title

    Mitigation of application DDoS attacks using ASNRI scheme for IP and MAC frames

  • Author

    Prabha, S. ; Anitha, R.

  • Author_Institution
    R&D Centre, Bharathiar Univ., Coimbatore, India
  • fYear
    2013
  • fDate
    21-22 Feb. 2013
  • Firstpage
    204
  • Lastpage
    209
  • Abstract
    With increasing trend in application services on large-scale internet scenario of both wired and wireless interface, intimidation to restrain the application service by Distributed Denial of Service (DDoS) attacks become a high-flying issue. Most of the present DDoS attacks resistance method work on application services in wired network and wireless network individually. No method is offered herewith for the two kinds of networks up to now. Though the present internet application services must switch between wired and wireless platform, well-matched resistance method for Distributed Denial of Service attacks have to be coined for better security which is the present requirement in the environment. With these issues in mind, the proposed model develops counter mechanism to mitigate the potency of the resource attacks and evaluate the efficacy. Application Service Network Request Identification (ASNRI) scheme is presented to provide an apparent demarcation of wired service and wireless services request, which is then fed to the Bayes packet classifier for its associated denial of service attack characteristics. From the Bayes packet classifier, resistance filters are stimulated to restrict denial of service attacks in the respective platform, that is., wired or wireless. The simulation of the proposed ASNRI scheme is conducted with NS-2 simulator to show its effectiveness of restricting Distributed Denial of Service attacks in terms of RESPONSE TIME, APPLICATION SERVICE THROUGHPUT, LOAD VARIANCE in the application server.
  • Keywords
    Internet; computer network security; pattern classification; protocols; ASNRI scheme; Bayes packet classifier; DDoS attack resistance method; IP frame; Internet protocol; MAC frame; NS-2 simulator; application DDoS attack mitigation; application service; application service network request identification; application service throughput; distributed denial-of-service attack; large-scale Internet scenario; load variance; medium access control; response time; wired network; wireless network; Computer crime; Entropy; Hidden Markov models; IP networks; Resistance; Servers; Throughput; Am; Bayes Packet Classifier and Gaussian Distribution; Hmm; IP and MAC frames;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Pattern Recognition, Informatics and Mobile Engineering (PRIME), 2013 International Conference on
  • Conference_Location
    Salem
  • Print_ISBN
    978-1-4673-5843-9
  • Type

    conf

  • DOI
    10.1109/ICPRIME.2013.6496473
  • Filename
    6496473