A Novel Method for Prevention of Bandwidth Distributed Denial of Service Attacks

K. Sangeeth, G. Dayanandam, Thota Venkat Narayana Rao · 2015

Distributed Denial of Service (DDoS) Attacks became a massive threat to the Internet. Traditional Architecture of internet is vulnerable to the attacks like DDoS. Attacker primarily acquire his army of Zombies, then that army will be instructed by the Attacker that when to start an attack and on whom the attack should be done. In this paper, different techniques which are used to perform DDoS Attacks, Tools that were used to perform Attacks and Countermeasures in order to detect the attackers and eliminate the Bandwidth Distributed Denial of Service attacks (B-DDoS) are reviewed. DDoS Attacks were done by using various Flooding techniques which are used in DDoS attack. The main purpose of this paper is to design an architecture which can reduce the Bandwidth Distributed Denial of service Attack and make the victim site or server available for the normal users by eliminating the zombie machines. Our Primary focus of this paper is to dispute how normal machines are turning into zombies (Bots), how attack is been initiated, DDoS attack procedure and how an organization can save their server from being a DDoS victim. In order to present this we implemented a simulated environment with Cisco switches, Routers, Firewall, some virtual machines and some Attack tools to display a real DDoS attack. By using Time scheduling, Resource Limiting, System log, Access Control List and some Modular policy Framework we stopped the attack and identified the Attacker (Bot) machines.

Read the paper · More papers on PaperTik