년 - 년
Detecting DDoS Attacks Using Randomness Check
한국정보통신설비학회 한국정보통신설비학회 세미나 시스템 보안과 Ddos 대응 방안 2009.11 pp.4-16
※ 기관로그인 시 무료 이용이 가능합니다.
4,500원
안드로이드 어플리케이션 취약점을 이용한 DDoS 공격 분석
한국융합보안학회 한국사이버테러정보전학회 학술발표대회 제7회 2011.12 pp.45-50
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
4,000원
DDoS 공격은 외부의 공격자가 일반 사용자들의 PC를 감염시킨 후 감염된 PC에서 특정 웹 사이트 나 서버에 대량의 트래픽을 전송하여 리소스를 고갈시키거나 네트워크 대역폭을 점유함으로써 서비스 를 마비시키는 공격으로, 완벽하게 막는 것이 대단히 어렵다. IDS(Intrusion Detection System:침입 탐지 시스템), IPS(Intrusion Prevention System:침입 방지 시스템), ITS(Intrusion Tolerance System), FW(Firewall) 또는 DDoS 전용 보안 장비 등을 이용하여 DDoS 공격을 막아내거나, 감내하려고 한다. 여러 종류의 보안 장비 비용 문제가 발생하기도 하고, 각 시스템 간의 연계성을 고려하지 않은 설치 로 제 기능을 발휘하지 못하기도 한다. 본 논문에서는 DDoS 공격에 대한 보안 장비의 효과적인 연계 와 대응 방법론을 제시한다. 설계된 방법론을 적용할 경우 기존의 네트워크 구조상에서보다 DDoS 공 격에 대한 차단 및 감내 효율이 실험을 통해 입증되었다. 따라서 차별화된 DDoS 공격을 대응 및 감 내하는 관제 방안을 본 연구를 통해 제시하고자 한다.
It is very difficult to completely block the DDoS attack, which paralyzes services by depleting resources or occupying the network bandwidth by transmitting a vast amount of traffic to the specific website or server from normal users' PCs that have been already infected by an outside attacker. In order to defense or endure the DDoS attack, we usually use various solutions such as IDS (Intrusion Detection System), IPS (Intrusion Prevention System), ITS (Intrusion Tolerance System), FW (Firewall), and the dedicated security equipment against DDoS attack. However, diverse types of security appliances cause the cost problem, besides, the full function of the equipments are not performed well owing to the unproper setting without considering connectivity among systems. In this paer, we present the effective connectivity of security equipments and countermeasure methodology against DDoS attack. In practice, it is approved by experimentation that this designed methdology is better than existing network structure in the efficiency of block and endurance. Therefore, we would like to propose the effective security control measures responding and enduring against discriminated DDoS attacks through this research.
카운팅 블룸 필터를 사용한 화이트리스트 사용자에의한 SIP DDoS 공격 탐지 및 대응 기법 KCI 등재
한국차세대컴퓨팅학회 한국차세대컴퓨팅학회 논문지 Vol.11 No.5 2015.10 pp.25-35
SIP(Session Initiation Protocol)는 멀티미디어 세션을 관리하는 응용계층 프로토콜로서, 인터넷 전화 등 많은응용서비스에서 활용되고 있다. SIP 대상 공격들 중 플러딩 공격은 가장 위협이 큰 공격이라고 할 수 있다. 이를해결하기 위하여 제안된 화이트리스트 기반의 탐지 및 대응 방법들은 화이트리스트에 없는 비정상 사용자로 부터의공격을 탐지하고 차단하는 것이 가능하지만, 정상 사용자로 위장하여 화이트리스트에 등록한 후에 플러딩 공격할 시에는 대응할 수 없다. 본 논문에서는 화이트리스트에 속한 사용자들로부터 발생되는 메시지를 대상으로 카운팅 블룸필터를 적용하여 정상 사용자에 의한 악의적인 플러딩 공격을 탐지하고, 이에 대응하는 방법을 제안한다. 실험 결과는 기존 방법에서는 화이트리스트에 속한 사용자로 부터의 공격을 탐지하지 못하나, 제안방법은 이를 효과적으로 탐지하고 대응함을 보여준다.
SIP(Session Initiation Protocol) is an application layer protocol to manage multimedia sessions, and has been utilized for various application services such as Internet telephony. Flooding attacks are one of the most dangerous attacks on SIP-based applications. To solve the problem, the whitelist-based schemes can detect and countermeasure against attacks from abnormal users. However, they can’t react against attacks by legitimate users who have been registered in the whitelist. In this paper, we propose a method to detect and countermeasure flooding attacks from legitimate users listed in the whitelist by applying counting Bloom filters to messages from them. Experimental results show that existing whitelist-based schemes can’t detect flooding attacks from users listed in the whitelist, while the proposed method can detect and countermeasure against those attacks very effectively.
Evaluation of Flow and Average Entropy Based Detection Mecha-nism for DDoS Attacks using NS-2 SCOPUS
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.10 No.5 2016.05 pp.139-146
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
Distributed Denial of Service (DDoS) attacks has started posing a serious threat to all sorts of businesses, which have used the power of internet to their credit. DDoS attacks have put a big question mark on the capabilities and reliability of the World Wide Web. The use of supreme techniques to combat the DDoS attacks has not been substantial enough to fight the distributed nature of attacks. Hackers have been successful in blocking the services and flooding traffic to servers, in spite of a tight check on the network. Thus, in the view of personal data being present on the web and the threat to global economy worth million dollars, it becomes really important to devise some new techniques that are self-capable enough to capture, trace and nullify the dangers posed by such attacks. This term paper talks about such solutions to combat DDoS attacks. Here, the flow entropy in combination with average entropy technique is used to detect an attack. It highlights how the loop holes of one technique are covered by the other, resulting in a considerable improvisation in the methods of how we deal with these attacks.
Novel Mechanism to Defend DDoS Attacks Caused by Spam
보안공학연구지원센터(IJSH) International Journal of Smart Home Vol.1 No.2 2007.07 pp.83-95
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
Corporate mail services are designed to perform better than public mail services. Fast mail delivery, large size file transfer as an attachments, high level spam and virus protection, commercial advertisement free environment are some of the advantages worth to mention. But these mail services are frequent target of hackers and spammers. Distributed Denial of service attacks are becoming more common and sophisticated. The researchers have proposed various solutions to the DDOS attacks. Can we stop these kinds of attacks with available technology? These days the DDoS attack through spam has increased and disturbed the mail services of various organizations. Spam penetrates through all the filters to establish DDoS attacks, which causes serious problems to users and the data. In this paper we propose a novel approach to defend DDoS attack caused by spam mails. This approach is a combination of fine tuning of source filters, content filters, strictly implementing mail policies, educating user, network monitoring and logical solutions to the ongoing attack. We have conducted several experiments in corporate mail services; the results show that this approach is highly effective to prevent DDoS attack caused by spam. The novel defense mechanism reduced 60% of the incoming spam traffic and repelled many DDoS attacks caused by spam.
Source-Based Filtering Scheme against DDOS Attacks
보안공학연구지원센터(IJDTA) International Journal of Database Theory and Application vol.1 no.1 2008.12 pp.9-20
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
IP address spoofing is employed by a lot of DDoS attack tools. Most of the current research on DDoS attack packet filtering depends on cooperation among routers, which is hard to achieve in real campaigns. Therefore, in the paper, we propose a novel filtering scheme based on source information in this paper to defend against various source IP address spoofing. The proposed method works independently at the potential victim side, and accumulates the source information of its clients, for instance, source IP addresses, hops from the server during attacks free period. When a DDoS attack alarm is raised, we can filter out the attack packets based on the accumulated knowledge of the legitimate clients. We divide the source IP addresses into )321(≤≤nn segments in our proposed algorithm; as a result, we can therefore release the challenge storage and speed up the procedure of information retrieval. The system which is proposed by us and the experiments indicated that the proposed method works effectively and efficiently.
Comprehensive Study of Various Techniques for Detecting DDoS Attacks in Cloud Environment
보안공학연구지원센터(IJGDC) International Journal of Grid and Distributed Computing Vol.8 No.3 2015.06 pp.119-126
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
Cloud computing is the most dynamic field of IT industry. It is becoming very famous due to its less resource consuming and higher output. Though Cloud computing is very vast and useful technology but it is not remained untouched from attackers or hackers. The most common attack notified on the cloud environment is DDoS attack. DDoS attacks i.e. Distributed Denial of service attacks happens on a cloud environment in such a way that, two or more than two attackers sends the multiple SOAP requests at the same cloud server and consume all the legitimate resources. From the study it has been concluded that, none a system is developed so far to prevent the DDoS attacks completely because even the detection of DDoS attacks is a major issue and prevention is a very big thing to achieve after detection and mitigation. This paper is focused on underlying the introduction about DDoS attacks and the next part of the paper is followed by the comparative analysis of the different techniques and algorithms used in detecting the DDoS attacks in cloud environment.
Using Adaptive Bandwidth Allocation Approach to Defend DDoS Attacks
보안공학연구지원센터(IJSEIA) International Journal of Software Engineering and Its Applications Vol.2 No.4 2008.10 pp.61-72
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
Denial of service attacks occur when the attacks are from a single host, whereas distributed denial of service attacks occur when multiple affected systems flood the bandwidth or resources of a targeted system. Although it is not possible to exempt entirely from denial of service or distributed denial of service attacks, we can limit the malicious user by controlling the traffic flow. In the paper, we propose to monitor the traffic pattern in order to alleviate distributed denial of service attacks. A bandwidth allocation policy will be adopted to assign normal users to a high priority queue and suspected attackers to a low priority queue. Simulations conducted in network simulator of our proposed priority queue-based scheme shows its effectiveness in blocking attacking traffic while maintaining constant flows for legitimate traffic.
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.9 No.7 2015.07 pp.17-36
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
Cloud computing is a technology which completely shifts the data to unaware Datacenter (DC) where the cloud service provider (CSP) is responsible for the subscribers’ data and its protection. Distributed Denial of Service (DDoS) is a kind of overload threat aims to subvert DC and their resources which leads to resource unavailable to legitimate requestors. In this paper we proposed an effective layered load balancing mechanism which scrutinizes the incoming requestors’ traffic at various layers and each layer outwits some kind of attack traffic. The early network traffic condition prediction paves the way to detect the threats earlier which in turn improves the availability. The significance of the proposed mechanism is detecting the higher rate of overload threats at earlier layers. Constant monitoring and stringent protocol setup for incoming traffic strengthens the proposed mechanism against several kinds of overload threats. Based on the traffic pattern of incoming requestors, the vulnerability is observed and outwitted at various layers. The simulation proved that the mechanism proposed is deployable at an attack-prone DC for resource protection, which would eventually benefit the DC economically as well.
A Novel Security Approach for Data Flow and Data Pattern Analysis to Mitigate DDOS Attacks in VANETs
보안공학연구지원센터(IJHIT) International Journal of Hybrid Information Technology Vol.8 No.8 2015.08 pp.113-122
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
The VANET security is an important issue with the rise of the automatically driven vehicle based technologies. The automatically driven vehicle based clusters are programmed for each vehicle to run individually by coordinating with all of the other nodes in the VANET cluster. The proposed model has been designed to detect and mitigate the DoS and DDoS attacks in the VANET clusters to avoid any of the misbehavior or mis-happening in the form of VANET node failure, collision or in any other form. The DDoS attack prevention algorithm works as the real time attack detection and overhead data filtering algorithm in order to protect against the DoS and DDoS attacks. The proposed model result has been obtained on the basis of network load, throughput, packet delivery ratio, etc. The experimental results have proved the efficiency of the proposed model in comparison with the existing models.
보안공학연구지원센터(IJFGCN) International Journal of Future Generation Communication and Networking vol.3 no.2 2010.06 pp.53-60
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
In this paper we focus on alleviating malicious traffic from DDoS attacks since many famous websites have been attacked by them and massive losses have been reported in recent years. We propose a Priority Queue-Based scheme to analyze the interval of the arrival times of incoming packets in order to distinguish malicious traffic from normal traffic and to take care of malicious attacks clogging the network. We use the network simulator, NS2, to assess the efficiency of the proposed scheme. Simulation results show that the proposed Priority Queue-based scheme not only effectively decreases the flows of malicious packets from DDoS attacks with various packet rates, but also provides smooth and constant flows for packets sent by normal users. Furthermore, our priority queue-based scheme performs much better than other schemes when the number of the DDoS nodes becomes large.
DDoS 의 교육기관 공격에 대한 예상 피해와 방어 전략
한국정보기술융합학회 한국정보기술융합학회논문지 제3권 제3호 2010.12 pp.197-206
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
기존의 DDoS 공격은 악의적인 목적을 가진 공격자가 해킹프로그램을 이용하여 공공기관이나 특정 기업에 대하여 무차별한 공격을 쉽게 행하고 있다. 특히 공격자는 수천에서 수만에 이르는 시스템을 해킹하여 악성 프로그램(Bot)을 설치하고 이 악성 프로그램들을 네트워크로 묶어 동시에 제어함으로써 자신의 목적을 위해 충실히 임무를 수행하는 좀비(Clinet) 시스템을 보유하게 된다. 이를 Botnet 이라고 하며 Botnet 은 공격자들의 제 3 의 악의적인 행위를 하기 위한 좀비 PC(Client)부대가 된다. 해커(Bot Master)들은 그 악성 프로그램(Bot)을 이용하여 특정사이트에 DDoS 공격을 수행하며 금전적인 이윤을 요구하기도 하는 등 그 악용 사례들이 다양해지고 있다. 본 연구는 기존에 행해지고 있는 DDoS 공격의 사례를 비교 하여 해킹 프로그램(Bot)의 악의적인 공격 범위를 교육기관에 포커스를 맞추어 예상 피해범위와 해결 방안에 대하여 제시한다.
독립 이중화 망 이용 기관 업무여건 개선을 위한 가상화 기반 DDoS 공격 탐지 정보유출방지 체계 구축 연구 KCI 등재
보안공학연구지원센터(JSE) 보안공학연구논문지 Vol.12 No.3 2015.06 pp.221-238
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
군 관련 대외기관에서는 정보유출방지를 위하여 다양한 정보보호방지체계를 도입하여 운용하고 있 다. 그럼에도 불구하고 군 관련 대외기관은 항상 군 관련 자료들이 노출될 위험에 놓여 있으며, 이 정보유출이 지금도 지속되고 있는 실정이다. 즉 많은 정보보호체계들이 사용자 불편을 통해 업무 비 효율성을 추구하고 있어 많은 취약점과 문제점을 갖고 있기 때문이다. 각 조직들이 이를 해결하기 위 해 많은 HW와 SW를 도입하고 있지만 강력한 통제는 조직의 비효율성만 증가시키는 결과를 초래하 였다. 그래서 본 논문에서는 가상화 기반의 정보보호체계 구축을 위한 Virtual Security Zone 모델을 제시 연구하였다. 가상화 개념을 군 전산망에 적용한 모델로 망분리를 통한 기밀성, 무결성을 높였으 며 DDoS 공격 대응 체계를 구축하여 가용성 향상을 추구하였다. 이를 통해 군 독립 이중화 망을 사 용하는 군 기관의 정보보호체계를 구축하는 새로운 방안 제시를 위한 선행연구자료로 활용될 것으로 판단한다.
In this paper, the Military organization are commonly used for a variety of information system network(ex: Military network, Internet, Local Internet). The Organization which uses independent redundant military network has always been exposed to the risk of leakage of military-related materials. In order to prevent data loss defense agencies are governed by the introduction of a variety of systems. And military information security system is currently has a number of vulnerabilities and issues. Military organization has introduced a number of hardware and software in order to solve problems and unplanned. However to strengthen the information security policy has been badly efficiency of organization military business. So in this paper, we study that information disclosure prevention system using Virtual Security Zone for improving business condition of organization which uses independent redundant military network. This model is applied to the military computer network virtualization concept raised the confidentiality and integrity via a separate network. And to establish a DDoS attack response system sought to improve availability.
Supervised learning-based DDoS attacks detection: Tuning hyperparameters
[Kisti 연계] 한국전자통신연구원 ETRI journal Vol.41 No.5 2019 pp.560-573
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
Two supervised learning algorithms, a basic neural network and a long short-term memory recurrent neural network, are applied to traffic including DDoS attacks. The joint effects of preprocessing methods and hyperparameters for machine learning on performance are investigated. Values representing attack characteristics are extracted from datasets and preprocessed by two methods. Binary classification and two optimizers are used. Some hyperparameters are obtained exhaustively for fast and accurate detection, while others are fixed with constants to account for performance and data characteristics. An experiment is performed via TensorFlow on three traffic datasets. Three scenarios are considered to investigate the effects of learning former traffic on sequential traffic analysis and the effects of learning one dataset on application to another dataset, and determine whether the algorithms can be used for recent attack traffic. Experimental results show that the used preprocessing methods, neural network architectures and hyperparameters, and the optimizers are appropriate for DDoS attack detection. The obtained results provide a criterion for the detection accuracy of attacks.
Blockchain-based IoT Authentication techniques for DDoS Attacks
[Kisti 연계] 한국컴퓨터정보학회 Journal of the Korea society of computer and information Vol.24 No.7 2019 pp.87-91
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
In the IoT(Internet of Things) environment, various devices are utilized and applied for different sites. But attackers can access easy to IoT systems, and try to operate DDoS(Distributed Denial-of-Service) attacks. In this paper, Sensor nodes, Cluster heads, and Gateways operates lightweight mutual authentication each others. Since authenticated sensor nodes and cluster heads only send transactions to Gateways, proposed techniques prevent DDoS attacks. In addition, the blockchain system contains secure keys to decrypt data from sensor nodes. Therefore, attackers can not decrypt the data even if the data is eavesdropped.
[Kisti 연계] 한국멀티미디어학회 멀티미디어학회논문지 Vol.19 No.2 2016 pp.411-417
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
Since the development of Graphic Processing Unit (GPU) in 1999, the development speed of GPUs has become much faster than that of CPUs and currently, the computational power of GPUs exceeds CPUs dozens and hundreds times in terms of decimal calculations and costs much less. Owing to recent technological development of hardwares, general-purpose computing and utilization using GPUs are on the rise. Thus, in this paper, we have identified the elements to be considered for the Smart Grid Security. Focusing on a Performance Improvement of the Basic Algorithm for the Stateful Inspection to Detect DDoS Attacks using CUDA. In the program, we compared the search speeds of GPU against CPU while they search for the suffix trees. For the computation, the system constraints and specifications were made identical during the experiment. We were able to understand from the results of the experiment that the problem-solving capability improves when GPU is used. The other finding was that performance of the system had been enhanced when shared memory was used explicitly instead of a global memory as the volume of data became larger.
네트워크 트래픽 분석과 기계학습에 의한 DDoS 공격의 탐지
[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2004 pp.1007-1010
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
본 논문에서는 분산 서비스거부 공격(DDoS)이 발생할 때 네트워크 트래픽의 특성을 분석하기 위해서 트래픽 비율분석법(TRA: Traffic Rate Analysis)을 제안하고 트래픽 비율분석법을 통해서 분석된 다양한 유형의 DDoS 공격의 특성을 기계학습(Machine Learning)을 이용해서 DDoS 공격의 탐지규칙을 생성하고 그 성능을 측정하였다. 트래픽 비율분석법은 감시대상 네트워크 트래픽에서 특정한 유형의 트래픽의 발생비율을 나타내며 TCP flag rate 와 Protocol rate 로 구분된다. 트래픽 비율분석법을 적용한 결과 각각의 DDoS 공격 유형에 따라서 매우 독특한 특성을 가짐을 발견하였다. 그리고, 분석된 데이터를 대상으로 세 개의 기계학습 방법(C4.5, CN2, Na?ve Bayesian Classifier)을 이용해서 DDoS 공격의 탐지규칙을 생성하여 DDoS 공격의 탐지에 적용했다. 실험결과, 본 논문에서 제안된 트래픽 비율분석법과 기계학습을 통한 DDoS 공격의 탐지방법은 매우 높은 수준의 성능을 나타냈다.
네트워크 트래픽 분석과 기계학습에 의한 DDoS 공격의 탐지
[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2004 pp.1007-1010
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
본 논문에서는 분산 서비스거부 공격(DDoS)이 발생할 때 네트워크 트래픽의 특성을 분석하기 위해서 트래픽 비율분석법(TRA: Traffic Rate Analysis)을 제안하고 트래픽 비율분석법을 통해서 분석된 다양한 유형의 DDoS 공격의 특성을 기계학습(Machine Learning)을 이용해서 DDoS 공격의 탐지규칙을 생성하고 그 성능을 측정하였다. 트래픽 비율분석법은 감시대상 네트워크 트래픽에서 특정한 유형의 트래픽의 발생비율을 나타내며 TCP flag rate 와 Protocol rate 로 구분된다. 트래픽 비율분석법을 적용한 결과 각각의 DDoS 공격 유형에 따라서 매우 독특한 특성을 가짐을 발견하였다. 그리고, 분석된 데이터를 대상으로 세 개의 기계학습 방법(C4.5, CN2, Na?ve Bayesian Classifier)을 이용해서 DDoS 공격의 탐지규칙을 생성하여 DDoS 공격의 탐지에 적용했다. 실험결과, 본 논문에서 제안된 트래픽 비율분석법과 기계학습을 통한 DDoS 공격의 탐지방법은 매우 높은 수준의 성능을 나타냈다.
[Kisti 연계] 한국전자통신연구원 전자통신동향분석 Vol.26 No.6 2011 pp.154-163
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
최근 이동통신 네트워크 기술의 발전과 고성능 이동단말의 출현으로 인하여 다양한 서비스가 제공되고 있으며, 이로 인하여 이동통신 기술은 통신 인프라에서 생활 인프라로 진화하고 있다. 그러나 이러한 이동통신 환경의 변화는 네트워크의 안정성과 가용성을 위협하는 보안 위협도 증대시키고 있다. 본 고에서는 알려진 이동통신 네트워크에 대한 DDoS 공격기술과 그 대응기술, 그리고 현재 이동통신 보안을 위한 상용 제품들을 소개하고 향후 이동통신 네트워크 DDoS 대응기술의 발전 방향을 살펴보고자 한다.
0개의 논문이 장바구니에 담겼습니다.
선택하신 파일을 압축중입니다.
잠시만 기다려 주십시오.