DocumentCode
1924467
Title
Mitigation of application DDoS attacks using ASNRI scheme for IP and MAC frames
Author
Prabha, S. ; Anitha, R.
Author_Institution
R&D Centre, Bharathiar Univ., Coimbatore, India
fYear
2013
fDate
21-22 Feb. 2013
Firstpage
204
Lastpage
209
Abstract
With increasing trend in application services on large-scale internet scenario of both wired and wireless interface, intimidation to restrain the application service by Distributed Denial of Service (DDoS) attacks become a high-flying issue. Most of the present DDoS attacks resistance method work on application services in wired network and wireless network individually. No method is offered herewith for the two kinds of networks up to now. Though the present internet application services must switch between wired and wireless platform, well-matched resistance method for Distributed Denial of Service attacks have to be coined for better security which is the present requirement in the environment. With these issues in mind, the proposed model develops counter mechanism to mitigate the potency of the resource attacks and evaluate the efficacy. Application Service Network Request Identification (ASNRI) scheme is presented to provide an apparent demarcation of wired service and wireless services request, which is then fed to the Bayes packet classifier for its associated denial of service attack characteristics. From the Bayes packet classifier, resistance filters are stimulated to restrict denial of service attacks in the respective platform, that is., wired or wireless. The simulation of the proposed ASNRI scheme is conducted with NS-2 simulator to show its effectiveness of restricting Distributed Denial of Service attacks in terms of RESPONSE TIME, APPLICATION SERVICE THROUGHPUT, LOAD VARIANCE in the application server.
Keywords
Internet; computer network security; pattern classification; protocols; ASNRI scheme; Bayes packet classifier; DDoS attack resistance method; IP frame; Internet protocol; MAC frame; NS-2 simulator; application DDoS attack mitigation; application service; application service network request identification; application service throughput; distributed denial-of-service attack; large-scale Internet scenario; load variance; medium access control; response time; wired network; wireless network; Computer crime; Entropy; Hidden Markov models; IP networks; Resistance; Servers; Throughput; Am; Bayes Packet Classifier and Gaussian Distribution; Hmm; IP and MAC frames;
fLanguage
English
Publisher
ieee
Conference_Titel
Pattern Recognition, Informatics and Mobile Engineering (PRIME), 2013 International Conference on
Conference_Location
Salem
Print_ISBN
978-1-4673-5843-9
Type
conf
DOI
10.1109/ICPRIME.2013.6496473
Filename
6496473
Link To Document