Repository logo

DDoSniffer: An attack detection tool detecting TCP-based distributed denial of service attack traffic at the agent machines

dc.contributor.authorLaurens, Vicky
dc.date.accessioned2013-11-07T18:13:59Z
dc.date.available2013-11-07T18:13:59Z
dc.date.created2006
dc.date.issued2006
dc.degree.levelMasters
dc.degree.nameM.Sc.
dc.description.abstractDistributed Denial of Service (DDoS) attacks are an important and challenging security threat. Despite of the availability of several defence mechanisms and ongoing academic research in the field, attackers handle to build a large network of agent machines. This research developed a tool, DDoSniffer, to tackle the DDoS attack by detecting ongoing attack traffic at the agent machines. Due to the diversity in DDoS attack strategies, it is not realistic to deal with all type of attacks with one single solution. DDoSniffer focuses on TCP-based attacks. Different scenarios were tested to evaluate the performance of DDoSniffer when detecting what we classified as connection attacks and bandwidth attacks. The former attacks generate connections with four packets or fewer. The latter attacks create connections with traffic ratios larger than usual. Detection is the minimum requirement of all defence mechanisms, and DDoSniffer is capable of detecting a broad range of attacks within seconds.
dc.format.extent74 p.
dc.identifier.citationSource: Masters Abstracts International, Volume: 45-05, page: 2654.
dc.identifier.urihttp://hdl.handle.net/10393/27384
dc.identifier.urihttp://dx.doi.org/10.20381/ruor-18680
dc.language.isoen
dc.publisherUniversity of Ottawa (Canada)
dc.subject.classificationEngineering, System Science.
dc.subject.classificationComputer Science.
dc.titleDDoSniffer: An attack detection tool detecting TCP-based distributed denial of service attack traffic at the agent machines
dc.typeThesis

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail ImageThumbnail Image
Name:
MR25797.PDF
Size:
6.19 MB
Format:
Adobe Portable Document Format