{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/105224"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/105224","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"An effective network flow prioritization approach in DDoS scenarios","abstract":"In the modern Internet, Distributed Denial-of-Service (DDoS) has been a constant threat to all web services. An attacker may send a flood of requests with a botnet to the victim system, so that the system will waste all resources processing the huge number of unnecessary requests generated by an attacker and will not be available to any normal user. To mitigate DDoS attacks, it is crucial for a defense mechanism to have a policy that can discriminate legitimate network flows from the malicious ones. Such a fairness policy will help prioritizing the legitimate flows and prevent the system from DDoS attacks. In this thesis, we present and compare the effectiveness of four different fairness policies using data collected from real-world DDoS scenarios on a commercial web server. Unlike previous prioritization schemes, our policies study the characteristics of the network flows and are proved to be effective.","abstract_html":"In the modern Internet, Distributed Denial-of-Service (DDoS) has been a constant threat to all web services. An attacker may send a flood of requests with a botnet to the victim system, so that the system will waste all resources processing the huge number of unnecessary requests generated by an attacker and will not be available to any normal user. To mitigate DDoS attacks, it is crucial for a defense mechanism to have a policy that can discriminate legitimate network flows from the malicious ones. Such a fairness policy will help prioritizing the legitimate flows and prevent the system from DDoS attacks. In this thesis, we present and compare the effectiveness of four different fairness policies using data collected from real-world DDoS scenarios on a commercial web server. Unlike previous prioritization schemes, our policies study the characteristics of the network flows and are proved to be effective.","abstract_has_math":false,"creators":["Liu, Shu"],"institution":"University of Illinois at Urbana-Champaign","degree_name":"M.S.","degree_level":"Thesis","degree_discipline":"Electrical & Computer Engr","degree_department":null,"school":null,"contributors":["Hu, Yih-Chun"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2019,"date_issued":"2019-08-23T20:48:18Z","date_published":"2019-08-23T20:48:18Z","updated_at":"2026-07-22T22:24:44Z","subjects":["Computer network security","DDoS"],"languages":["en"],"rights":["Copyright 2019 Shu Liu"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"http://hdl.handle.net/2142/105224","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Hu, Yih-Chun"]},{"key":"dc:creator","label":"Author","values":["Liu, Shu"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2019-08-23T20:48:18Z","2021-08-24T09:15:35Z","2019-04-18","2019-05"]},{"key":"dc:type","label":"Dc Type","values":["text"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Electrical & Computer Engr"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Thesis"]},{"key":"thesis:degree_name","label":"Degree Name","values":["M.S."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Computer network security","DDoS"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2019 Shu Liu"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["http://hdl.handle.net/2142/105224"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["In the modern Internet, Distributed Denial-of-Service (DDoS) has been a constant threat to all web services. An attacker may send a flood of requests with a botnet to the victim system, so that the system will waste all resources processing the huge number of unnecessary requests generated by an attacker and will not be available to any normal user. To mitigate DDoS attacks, it is crucial for a defense mechanism to have a policy that can discriminate legitimate network flows from the malicious ones. Such a fairness policy will help prioritizing the legitimate flows and prevent the system from DDoS attacks. In this thesis, we present and compare the effectiveness of four different fairness policies using data collected from real-world DDoS scenarios on a commercial web server. Unlike previous prioritization schemes, our policies study the characteristics of the network flows and are proved to be effective.","Submission published under a 24 month embargo labeled 'Closed Access', the embargo will last until 2021-05-01","The student, Shu Liu, accepted the attached license on 2019-04-18 at 11:27.","The student, Shu Liu, submitted this Thesis for approval on 2019-04-18 at 11:41.","This Thesis was approved for publication on 2019-04-18 at 17:56.","DSpace SAF Submission Ingestion Package generated from Vireo submission #13742 on 2019-08-22 at 16:23:11","Made available in DSpace on 2019-08-23T20:48:18Z (GMT). No. of bitstreams: 2 LIU-THESIS-2019.pdf: 360898 bytes, checksum: ecc904ff86e9ed16e8db5974684d5d92 (MD5) LICENSE.txt: 4204 bytes, checksum: 4574af43f58a224f1f49cd143b0be842 (MD5) Previous issue date: 2019-04-18","Embargo set by: Seth Robbins for item 112346 Lift date: 2021-08-23T20:48:32Z Reason: Author requested closed access (OA after 2yrs) in Vireo ETD system","Limited Restriction Lifted for Item 112346 on 2021-08-24T09:15:35Z."]},{"key":"dc:format","label":"Dc Format","values":["application/pdf"]},{"key":"dc:title","label":"Title","values":["An effective network flow prioritization approach in DDoS scenarios"]}]}],"canonical_facts":{"dc:contributor":["Hu, Yih-Chun"],"dc:creator":["Liu, Shu"],"dc:date":["2019-08-23T20:48:18Z","2021-08-24T09:15:35Z","2019-04-18","2019-05"],"dc:description":["In the modern Internet, Distributed Denial-of-Service (DDoS) has been a constant threat to all web services. An attacker may send a flood of requests with a botnet to the victim system, so that the system will waste all resources processing the huge number of unnecessary requests generated by an attacker and will not be available to any normal user. To mitigate DDoS attacks, it is crucial for a defense mechanism to have a policy that can discriminate legitimate network flows from the malicious ones. Such a fairness policy will help prioritizing the legitimate flows and prevent the system from DDoS attacks. In this thesis, we present and compare the effectiveness of four different fairness policies using data collected from real-world DDoS scenarios on a commercial web server. Unlike previous prioritization schemes, our policies study the characteristics of the network flows and are proved to be effective.","Submission published under a 24 month embargo labeled 'Closed Access', the embargo will last until 2021-05-01","The student, Shu Liu, accepted the attached license on 2019-04-18 at 11:27.","The student, Shu Liu, submitted this Thesis for approval on 2019-04-18 at 11:41.","This Thesis was approved for publication on 2019-04-18 at 17:56.","DSpace SAF Submission Ingestion Package generated from Vireo submission #13742 on 2019-08-22 at 16:23:11","Made available in DSpace on 2019-08-23T20:48:18Z (GMT). No. of bitstreams: 2 LIU-THESIS-2019.pdf: 360898 bytes, checksum: ecc904ff86e9ed16e8db5974684d5d92 (MD5) LICENSE.txt: 4204 bytes, checksum: 4574af43f58a224f1f49cd143b0be842 (MD5) Previous issue date: 2019-04-18","Embargo set by: Seth Robbins for item 112346 Lift date: 2021-08-23T20:48:32Z Reason: Author requested closed access (OA after 2yrs) in Vireo ETD system","Limited Restriction Lifted for Item 112346 on 2021-08-24T09:15:35Z."],"dc:format":["application/pdf"],"dc:identifier":["http://hdl.handle.net/2142/105224"],"dc:language":["en"],"dc:rights":["Copyright 2019 Shu Liu"],"dc:subject":["Computer network security","DDoS"],"dc:title":["An effective network flow prioritization approach in DDoS scenarios"],"dc:type":["text"],"thesis:degree_discipline":["Electrical & Computer Engr"],"thesis:degree_level":["Thesis"],"thesis:degree_name":["M.S."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:24:44Z"}