Investigation Model for Ddos Attack Detection in Real-Time

Investigating traffic of distributed denial of services (DDoS) attack requires extra overhead which mostly results in network performance degradation. This study proposes an investigation model for detecting DDoS attack in real-time without causing negative degradation against network performance. T...

Full description

Saved in:
Bibliographic Details
Main Author: Ahmed, Abdulghani Ali
Format: Article
Language:English
Published: Penerbit UMP 2015
Subjects:
Online Access:http://umpir.ump.edu.my/id/eprint/11843/1/Investigation%20Model%20For%20Ddos%20Attack%20Detection%20In%20Real-Time.pdf
http://umpir.ump.edu.my/id/eprint/11843/
http:// dx.doi.o rg/10.15282/ijsecs.1.2015.8.0008
Tags: Add Tag
No Tags, Be the first to tag this record!
Description
Summary:Investigating traffic of distributed denial of services (DDoS) attack requires extra overhead which mostly results in network performance degradation. This study proposes an investigation model for detecting DDoS attack in real-time without causing negative degradation against network performance. The model investigates network traffic in a scalable way to detect user violations on quality of service regulations. Traffic investigation is triggered only when the network is congested; at that exact moment, burst gateways actually generate a congestion notification to misbehaving users. The misbehaving users are thus further investigated by measuring their consumption ratios of bandwidth. By exceeding the service level agreement bandwidth ratio, user traffic is filtered as DDoS traffic. Simulation results demonstrate that the proposed model efficiently monitors intrusive traffic and precisely detects DDoS attack.