Destination Address Entropy based Detection and Traceback Approach against Distributed Denial of Service Attacks

Abhinav Bhandari, Amrit Lal Sangal, Krishan Kumar · International Journal of Computer Network and Information Security · 2015

With all the brisk growth of web, distributed denial of service attacks are becoming the most serious issues in a data center scenarios where lot many servers are deployed.A Distributed Denial of Service attack generates substantial packets by a large number of agents and can easily tire out the processing and communication resources of a victim within very less period of time.Defending DDoS problem involved several steps from detection, characterization and trace back in order todomitigation.The contribution of this research paper is a lot more.Firstly, flooding based DDoS problems is detected using obtained packets based entropy approach in a data center scenario.Secondly entropy based trace back method is applied to find the edge routers from where the whole attack traffic is entering into the ISP domain of the data center.Various simulation scenarios using NS2 are depicted in order to validate the proposed method using GT-ITM primarily based topology generators.Information theory based metrics like entropy; average entropy and differential entropy are used for this purpose.

Read the paper · More papers on PaperTik