Comparison of Linux Filtering Tools for Mitigation of DDoS Attacks
Petr Blažek, Tomáš Gerlich, Zdeněk Martinásek, Jakub Frolka · 2018
Every year, the intensity and quantity of Distributed Denial of Service (DDoS) attacks realized is incessantly increasing, that is confirmed by companies such as Kaspersky, Imperva or Verisign. Moreover, this reality is also confirmed by the published losses of victims. The popularity of these attacks is mainly trigger for the simplicity of realization therefore the actual costs of the attack realization are cheap. The main goal of this article is to compare open source tools for network data processing. This research is realized in order to identify the most effective tool including the settings that will be implemented into DDoS mitigation system. The final system provide adaptive network filtering based on the decomposition of network traffic and filtering utilizing commodity servers.