Attack detection of distributed denial of service based on Splunk
Te‐Jen Su, Shih‐Ming Wang, Yi-Feng Chen, Chao‐Liang Liu · 2016
This study utilizes the open source testing tool, Hping3, and the network analysis tool, Scapy, to simulate DDoS flood, reflection, and amplification attacks. We used the data generated from the attacks with the Splunk platform to conduct data analysis to quickly identify attacks and predict potential dangers that could arise. The analysis results were used in tests conducted on real network environments to determine the types of DDoS attacks. Visual IP mapping was then used to determine actions that could be taken.