Back to Search Start Over

DDoS Flood and Destination Service Changing Sensor

Authors :
Fu-Hau Hsu
Chia-Hao Lee
Chun-Yi Wang
Rui-Yi Hung
YungYu Zhuang
Source :
Sensors, Vol 21, Iss 6, p 1980 (2021)
Publication Year :
2021
Publisher :
MDPI AG, 2021.

Abstract

In this paper, we aim to detect distributed denial of service (DDoS) attacks, and receive a notification of destination service, changing immediately, without the additional efforts of other modules. We designed a kernel-based mechanism to build a new Transmission Control Protocol/Internet Protocol (TCP/IP) connection smartly by the host while the users or clients not knowing the location of the next host. Moreover, we built a lightweight flooding attack detection mechanism in the user mode of an operating system. Given that reinstalling a modified operating system on each client is not realistic, we managed to replace the entry of the system call table with a customized sys_connect. An effective defense depends on fine detection and defensive procedures. In according with our experiments, this novel mechanism can detect flooding DDoS successfully, including SYN flood and ICMP flood. Furthermore, through cooperating with a specific low cost network architecture, the mechanism can help to defend DDoS attacks effectively.

Details

Language :
English
ISSN :
14248220
Volume :
21
Issue :
6
Database :
Directory of Open Access Journals
Journal :
Sensors
Publication Type :
Academic Journal
Accession number :
edsdoj.1a819ec314d44a86bb85c9f50c28e4a7
Document Type :
article
Full Text :
https://doi.org/10.3390/s21061980