DDoS(Distributed Denial of Service) attack is arising as the most serious problem among current problems of computer security. With the development of attack tools and increasement in zombie computer, a threat to security is larger and consequently In...
DDoS(Distributed Denial of Service) attack is arising as the most serious problem among current problems of computer security. With the development of attack tools and increasement in zombie computer, a threat to security is larger and consequently Internet is recently exposed to many DDoS attacks. Due to varying attacks circumventing vulnerability of equipment and the development of attack tools using the abovemethod, new DDoS attacks have increased. Therefore, it is very important to detect and prevent the attacks before paralyzing the system or network. Therefore this experimentation is focusedon the detection mechanism of DDoS attack that can minimize damages by perceiving attack characteristics.
In this thesis simulated attacks on the network by means of DDoS attack tool that is most frequently used and has various types of attacks, is applied. For traffic collection, characteristics of attack traffic protocols were analyzed by using Wireshark, and based on this, three kinds(average traffic volume, attack traffic volume by protocols, mean ratio of change by protocols) of marginal value in the system were established to detect attack. To estimate or verify detection efficiency of suggested system, It was compared with commercial programs.
Detection mechanism suggested in this result has the following advantages. It analyzed characteristics on the network through various attacks and detected exactly by using three kinds of marginal value. Using step-by-step detection mechanism for attacks, it didn’t burden network and system. It could set up a policy suitable for the actual system by establishing marginal value through many actual attacks and showed improved detection performance since a suggested detection model decreased the rate of wrong detection.