Journal of Advances in Information Technology, Vol 3, No 2 (2012), 120-129, May 2012
doi:10.4304/jait.3.2.120-129

A Dynamic Bandwidth Assignment Approach Under DDoS Flood Attack

Raman Singh, Amandeep Verma

Abstract


Distributed denial-of-service (DDoS) attacks are a major threat to the Internet. A lot of research is going on to detect, prevent and trace back DDoS attacks. Most of researchers are busy in post attack forensics which comes after the attack has been occurred but nobody is talking about how to design a system which can tolerate such attacks. In this paper we have suggested a approach for dynamic assignment of bandwidth in order to sustain the server. Basic idea is to examine genuine IP user’s traffic flow based on volume. Divide traffic in two categories of genuine traffic and malicious traffic and assign bandwidth as per category. The idea is to design a system which can give services even when the server is under attack. However some performance will degrades but overall Quality of services will be acceptable. A new formula also has been derived for dynamic bandwidth assignment which is based on number of genuine users and traffic volumes of users and attackers.


Keywords


Bandwidth Management, Dynamic Bandwidth Assignment, QoS Controlling Factor

References


Yuval, Fledel. Uri, Kanonov. Yuval, Elovici. Shlomi, Dolev. Chanan,. "Google Android: A Comprehensive Security Assessment". IEEE Security & Privacy (IEEE) (in press). doi:10.1109/MSP.2010.2. ISSN 1540-7993.

Paul J. Criscuolo. “Distributed Denial of Service Trin00, Tribe Flood Network, Tribe Flood Network 2000, And Stacheldraht CIAC-2319”. Department of Energy Computer Incident Advisory Capability (CIAC), UCRL-ID-136939, Rev. 1., Lawrence Livermore National Laboratory.

Boyle Phillip “Distributed Denial of Services” http://www.sans.org/y2k/DDoS.htm.

Barros C. “ICMP Trace back message” http://research.att.com/~smb/talks.

Senie Ferguson, D. “Denial of Services tools” http://www.cert.org/advisories/ca-98-13-tcp-denial-of-service.html.

Mirkovic Jelena, Hussain lefiya, Reiher Peter, “ Accurately Measuring Denial of Service in Simulation and Testbed Experiments”, IEEE Transactions on Dependable and Secure Computing, Vol 2 No.2, April-June 2009. Pg. No. 81-95.

Li Ming, Li Jung, zhao Wei,” Simulation Study of Flood Attacking of DDoS”, International Conference on Internet Computing in Science and Engineering, IEEE 2008. Pg no. 286-293.

Khazan Golriz, Azgomi M.A., “ A Distributed Attack Simulation for Quantitative Security Evaluation using SimEvents”, IEEE 2009 Iran university of Science and technology,Tehran.

Harada Shigeaki, Kawahara Ryoichi, “ A Method of Detecting Network Anomalies In Cyclic Traffic”, IEEE GLOBCOM 2008.

Takemori Keisuke, Nishigaki Masakatsu, “ Detection of Bot Infected PCs Using Destination based IP and Domain Whitelists during a Non-Operating Term”, IEEE GLOBCOM -2008.

Goldstein Markus, Reif Matthias, Stahl armin, Breuel Thomas,” Server Side Protection of Source IP Address using Density Estimation”, International Conference on Availability, Reliability And Security. IEEE 2009.

Tupakula U.K., Varadharajan Vijay, Vuppala S.K., “ SBAC : Service Based Access Control”, 14th IEEE International Conference on Engineering of Complex Computer Systems, IEEE 2009.

Swain B.R., Sahoo B.S., “ Mitigating DDos attack and Savin Computational Time using s Probabilistic approach and HCF method”, Department of Computer Science and Engineering, National Institute of Technology, Rourkela, Orissa.2009 IEEE International Advance Computing Conference( IACC 2009).

Wang H., Jin C., Shin K.G., “ Defence Against Spoofed IP Traffic Using Hop-Count Filtering”, IEEE/ACM Transactions On Networking, Vol 15, No. 1, February 2007.

N. Venkatesu, Chakravarthy Deepan, “ An Effective Defence Against Distributed Denial of Service in Grid”, International Conference on Emerging Trends in Engineering and Technology, IEEE2008.

Stefanidis K., Serpanos D.N., “ Implementing Filtering and Traceback Mechanism for Packet – Marking IP- Trace back Schemes against DDoS Attacks”, 2008 International Conference “ Intelligent Systems”.

Kumar Sanjeev, “ Smurf Based Distributed Denial of Service Attack Amplification in Internet”, Second International Conference on Internet Monitoring and

Protection ( ICIMP 2007) IEEE 2007.

He Li, Tang Binhua, “ Available Bandwidth Estimation and its Application in Detection of DDoS Attacks”, ICCS 2008.

] Paruchuri Varnsi, Durresi Arjan, Chellppan Sriram, “ TTL Based Packet Marking for IP Traceback”, IEEE GLOBCOM 2008.

Clark C. “Insertion, evasion and denial of service : eluding network detection” http://clark.net/~roesch/idspaper.html.

Evans John, Filsfils, Clarence, “Deploying IP and MPLS QoS for Multiservice Networks: Theory and Practice" Morgan Kaufmann, 2007.

Campos F.H., Jeffay Kevin, Smith F.D., “ Tracking the Evolution of Web Traffic: 1995-2003”, IEEE/ACM International Symposium on Modeling, Analysis, and Simulation of Computer and Telecommunication Systeem(MASCOTS), Orlando FL, October 2003, Page 16-25.

Wang Shen, Guo Rui, “ GA- Based Filtering Algorithm to Defend against DDoS Attack in High Speed Network”, International Conference on Natural Computation IEEE 2008.

B. B. Gupta, R. C. Joshi, and Manoj Misra, "Prediction of Number of Zombies in a DDoS Attack using Polynomial Regression Model", Journal of advances in information technology, Vol 2, No. 1, FEBRUARY 2011, pp 57-62.

N. Bhalaji, Dr. A. Shanmugam, "Defense Strategy Using Trust Based Model to Mitigate Active Attacks in DSR Based MANET", Journal of advances in information technology, Vol 2, No. 2, MAY 2011, pp 92-98.

Eddaoui Ahmed, Mezrioui Abdellatif, “ Defeat the Network Attack by Using Active Network Approach”, IEEE 2006.

Gao Zhiqiang, Ansari Nirwan,” Differentiating Malicious DDoS Attack Traffic from Normal TCL Flows by Proactive Tests”, IEEE Communication Letters, Vol 20 No. 11, November 2006.

Paruchuri Vamsi, Durresi Arjan, Barolli Leonard, “ FAST : Fast Autonomous System Traceback”, International Conference on Advanced Networking and Applications(AINA 2007).

Shevtekar Amey, Ansari Nirwan, “ Is It Congestion or a DDoS Attack” IEEE Communication Letters, Vol. 13, No. 7 , JULY 2009.

Hasan Muhhamad, Nadeem Kamran, Khan Shoab, “ Optimal Placement of Detection Nodes against Distributed Denial of Service Attack”, International Conference on Advanced Computer Control, IEEE 2008.

Li Ming, Li Jung, zhao Wei,” Simulation Study of Flood Attacking of DDoS”, International Conference on Internet Computing in Science and Engineering, IEEE 2008. Pg no. 286-293.

Liu Chung-Hsin, Lo Chun-Lin,” The Simulation for VOIP DDoS attack”, International Conference on MultiMedia and Information Technology, IEEE 2008. Pg. No. 280-283.

Fu Zhang, Tsigas Philippas,” Mitigating Distributed Denial of Service Attacks in Multyparty Applications in the presence of Clock Drifts”, Symposium on Reliable Distributed Systems, IEEE 2008. Pg no. 63-72.


Full Text: PDF


Journal of Advances in Information Technology (JAIT, ISSN 1798-2340)

Copyright @ 2006-2013 by ACADEMY PUBLISHER – All rights reserved.