Browse > Article
http://dx.doi.org/10.5762/KAIS.2014.15.11.6845

System Design of IDS for DDoS Detect and Defense  

Hong, Seong-Sik (Dept. of Internet Security, HyeJeon College)
Publication Information
Journal of the Korea Academia-Industrial cooperation Society / v.15, no.11, 2014 , pp. 6845-6848 More about this Journal
Abstract
This paper proposes a system design of IDS for detecting and defending against DDoS attacks on a network. The proposed system has three parts; the Alert, Attack Analyzer and Defense agent. When the server resource was reduced too much by incoming traffic, the Alert Agent sends message and traffic information to the Attack Analyzer. The message and traffic to the Attack analyzer include only the sender & receiver address and packet numbers for minimizing the overload of Attack Analyzer. Message Received Attack Analyzer investigates the Message. If the pattern of traffic is the same as the DDoS Style, the Analyzer sends a message to the Defense Agent to block that traffic. In this system, at the serious state of the server-down, the Attack analyzer uncovers the DDoS Attacker and send a message to the Defense Agent to block that traffic. This works for server reactivation as soon as possible.
Keywords
DDoS Attack; IDS;
Citations & Related Records
Times Cited By KSCI : 2  (Citation Analysis)
연도 인용수 순위
1 Jin-won Seo, Jin Kwak, "The Design of Anti-DDoS System using Defense on Depth ", Journal of the Korean Institute of Information Security and Cryptology, 22-3, pp,679-689, 2012/06.   과학기술학회마을
2 Jeonn Yong Hee, Jang Jong Su, Oh Jin Tae, "DDoS Attack & Defence Tequnics", KIISC, 19-3, pp.46-57, 2009/06.
3 Jeong Chung Gyo, Oh Ji Hyeon, "Defence of Distributed Denial of Service with User Cooperation", KICS, No.33-4, pp.136-142, 2008/04.
4 Ruoyu Yan, Qinghua Zheng, Haifei Li, "Combining Adaptive Filtering and IF Flows to Detect DDoS Attacks within a Router", KSII Transactions on Internet and Information Systes(TIIS), vol.4, no.3, pp.428-451, June, 2010.   과학기술학회마을   DOI
5 Yoon Young Jin, Lee Jung Il, Gu Kyeong ok, Oh Chang Seok, "DDoS Attack Detect by Traffic variance", KEIA, book No.7, pp.123-128, 2010/11
6 Choi Yang Seo, Oh Jin Tae, Jang Jong Su, Ryou Jae Cheol, "A research of Total Defence system for DDoS Attack", KIISC, No.19-5, pp.11-20, 2009/10.
7 Yang Dae Il, Fundamental of Information Security, HanBit Academy