NJIT
Flow-oriented anomaly-based detection of denial of service attacks with flow-control-assisted mitigation
Abstract
dc:description.abstractFlooding-based distributed denial-of-service (DDoS) attacks present a serious and major threat to the targeted enterprises and hosts. Current protection technologies are still largely inadequate in mitigating such attacks, especially if they are large-scale. In this doctoral dissertation, the Computer Network Management and Control System (CNMCS) is proposed and investigated; it consists of the Flow-based Network Intrusion Detection System (FNIDS), the Flow-based Congestion Control (FCC) System, and the Server Bandwidth Management System (SBMS). These components form a composite defense system intended to protect against DDoS flooding attacks. The system as a whole adopts a flow-oriented and anomaly-based approach to the detection of these attacks, as well as a control-theoretic approach to adjust the flow rate of every link to sustain the high priority flow-rates at their desired level. The results showed that the misclassification rates of FNIDS are low, less than 0.1%, for the investigated DDOS attacks, while the fine-grained service differentiation and resource isolation provided within the FCC comprise a novel and powerful built-in protection mechanism that helps mitigate DDoS attacks.
Degree
thesis:*- Name thesis:degree_name
- Doctor of Philosophy in Electrical Engineering - (Ph.D.)
- Discipline thesis:degree_discipline
- Electrical and Computer Engineering
- Year
- 2006
Author and committee
dc:creator, dc:contributor.*- Author dc:creator
-
- Song, Sui
- Contributors dc:contributor
-
- Constantine N. Manikopoulos
- MengChu Zhou
- Roberto Rojas-Cessa
Subjects
dc:subject × 5Identifiers
dc:identifier.*- Repository record dc:identifier
- https://digitalcommons.njit.edu/dissertations/755
- OAI identifier oai:identifier
- oai:digitalcommons.njit.edu:dissertations-1810