DSpace Repository

A DEFENSE OF DNS AMPLIFICATION ATTACK VIA FLOW-BASED ANALYSIS WITH SDN

Show simple item record

dc.contributor.author AHMAD ARIFF AIZUDDIN MOHD ATAN
dc.date.accessioned 2018-11-28T01:56:06Z
dc.date.available 2018-11-28T01:56:06Z
dc.date.issued 2018-11-28
dc.identifier.uri http://ir.unikl.edu.my/jspui/handle/123456789/20623
dc.description.abstract The purpose of this research is to seek and propose alternative detection and mitigatin methods which can be used to create a defense of DNS amplification attack. Network traces obtained from University of Twente, Netherlands [2] have been used in this research. The existing methodology for DDoS attack detection and traffic mitigation using flow statistics has been adopted in this research. Properties of the proposed framework include; exporting flow information from an exporter to a collector; importing flow statistics of normal and abnormal DNS traffic; processing collected flow statistics by filtering both benign and malicious traffic according to DNS application data; check change of statistics by comparing both filtered traffic via an analyzer. Experimental results suggested that the proposed method manages to detect suspicious traffic without entailing huge DNS response by using flexible flow, and decelerate amplified traffic without intruding normal DNS operation by using security-centric SDN. A comparative study was also carried out and it showed that the proposed approach has performed better in terms of the detection time and accuracy. This research was conducted based on limited resources and variables due to hardware constraints and the lack of publicly available dataset, apart from the ones that are mentioned above [2]. Thus, the obtained results are applicable only to the study domain with selected network traces. This research has introduced the application of flow-based monitoring with flow-based configuration technologies in providing substitute solution to timely detect and reasonably mitigate DNS amplification attack. en_US
dc.language.iso en en_US
dc.title A DEFENSE OF DNS AMPLIFICATION ATTACK VIA FLOW-BASED ANALYSIS WITH SDN en_US
dc.type Thesis en_US
dc.theses.semester July 2017 en_US
dc.theses.course Degree of Master of Information Technology en_US


Files in this item

This item appears in the following Collection(s)

Show simple item record

Search DSpace


Advanced Search

Browse

My Account