scieee Science in your language
[en] (orig)

Scalable DDoS mitigation system for data centers

Abstract

Abstract Distributed Denial of Service attacks (DDoS) have been used by attackers for over two decades because of their effectiveness. This type of the cyber-attack is one of the most destructive attacks in the Internet. In recent years, the intensity of DDoS attacks has been rapidly increasing and the attackers combine more often different techniques of DDoS to bypass the protection. Therefore, the main goal of our research is to propose a DDoS solution that allows to increase the filtering capacity linearly and allows to protect against the combination of attacks. The main idea is to develop the DDoS defense system in the form of a portable software image that can be installed on the reserve hardware capacities. During a DDoS attack, these servers will be used as filters of this DDoS attack. Our solution is suitable for data centers and eliminates some lacks of commercial solutions. The system employs modular DDoS filters in the form of special grids containing specific protocol parameters and conditions.

Read accessible full text

Scalable DDoS mitigation system for data centers

Author: Martinásek, Zdeněk
Publisher: Vysoká škola báňská - Technická univerzita Ostrava
Year: 2015
DOI: 10.15598/aeee.v13i4.1531
Source: https://dspace.vsb.cz/bitstreams/d0d35b41-bbd7-42d1-9801-0f7bc80f29df/download
INFORMATION AND COMMUNICATION TECHNOLOGIES AND SERVICES VOLUME: 13 |NUMBER: 4 |2015 |SPECIAL ISSUE
Scalable DDoS Mi iga ion Sys em o Da a Cen e s
Zdenek MARTINASEK
Depa men o Telecommunica ions, Facul y o Elec ical Enginee ing and Communica ion,
B no Uni e si y o Technology, Technicka 12, 616 00 B no, Czech epublic
[email p o ec ed]
DOI: 10.15598/aeee. 13i4.1531
Abs ac . Dis ibu ed Denial o Se ice a acks
(DDoS) ha e been used by a acke s o o e wo
decades because o hei e ec i eness. This ype o he
cybe -a ack is one o he mos des uc i e a acks in
he In e ne . In ecen yea s, he in ensi y o DDoS
a acks has been apidly inc easing and he a acke s
combine mo e o en di e en echniques o DDoS o by-
pass he p o ec ion. The e o e, he main goal o ou e-
sea ch is o p opose a DDoS solu ion ha allows o in-
c ease he il e ing capaci y linea ly and allows o p o-
ec agains he combina ion o a acks. The main idea
is o de elop he DDoS de ense sys em in he o m o
a po able so wa e image ha can be ins alled on he
ese e ha dwa e capaci ies. Du ing a DDoS a ack,
hese se e s will be used as il e s o his DDoS a -
ack. Ou solu ion is sui able o da a cen e s and elim-
ina es some lacks o comme cial solu ions. The sys em
employs modula DDoS il e s in he o m o special
g ids con aining speci ic p o ocol pa ame e s and con-
di ions.
Keywo ds
Da a cen e , DDoS, p o ec ion.
1. In oduc ion
Nowadays, he isk o cybe -a acks ha a e aimed a
go e nmen , companies, news media o end use s ep-
esen s a eal h ea . Acco ding o he s udies ealized
annually, he mos commonly used echniques o cybe -
a acks a e DoS (Denial o Se ice) and SQL (S uc-
u ed Que y Language) injec ion (I is a s a is ic o
ac ually ealized a acks). DoS a acks can be simply
di ided in o wo basic ypes [1]: Flooding a acks and
Logical a acks. In Flooding DoS a acks, an a acke
sends a la ge amoun o a ic o consume CPU (Cen-
al P ocessing Uni ) o he bandwid h o he ic im.
The DoS a ack consumes he esou ces o he ic im’s
se e o ne wo k in o de o deg ade a pe o mance
o cause a se e c ash. Flooding a acks ake ad an-
age o he weaknesses o he communica ion p o ocols
such as TCP (T ansmission Con ol P o ocol) [2], [3],
UDP (Use Da ag am P o ocol) [4], [5], ICMP (In e -
ne Con ol Message P o ocol)[6], FTP (File T ans e
P o ocol) [2], SIP (Session Ini ia ion P o ocol) [7] o
HTTP (Hype ex T ans e P o ocol) [8]. Logical a -
acks use weaknesses in applica ions o so wa e used
a he ic im’s side. The a acke sends only a ew
messages ha abuse he weaknesses o he so wa e in
o de o disable o c ash he a ge machine. The DoS
a ack is usually pe o med by a ne wo k node (e.g. a
pe sonal compu e ) seized by he a acke [1]. These
ne wo k nodes a e called zombies o bo ne s and hey
a e no comple ely unde he con ol o he a acke .
I causes ha he a ack consis s o la ge quan i ies o
eques s (usually hund eds o housands), wha can be
ealized om all o e he wo ld. The a acke c ea es
a necessa y in as uc u e o bo ne s simply by using
T ojan ho ses o o he malwa e, ha a e unning on
he in ec ed ne wo k nodes. Dis ibu ed Denial o Se -
ice a acks a e pe o med by mul iple nodes. Cu -
en ly, he in as uc u e o bo ne s is ge ing bigge
and eady o a ack any ime. Mo e de ails abou DDoS
a acks can be ound in su ey pape s [9], [10].
In p ac ice, DDoS a acks ha e di e en use cases
and a ge s. We summa ize hese obse a ions in he
ollowing poin s:
•Denial o Se ice - i ep esen s a classic usage
o DDoS a acks. The compe ing companies a e
usually he a ge in his use case and he a acke
wan s o cause la ge inancial losses and impai he
company’s epu a ion. Go e nmen ne wo ks and
media se e s a e ano he ypical a ge o hese
a acks.
•Masking o cybe -a acks - in his case, he a -
acke uses a DDoS a ack o mask he “ ue” a -
c
2015 ADVANCES IN ELECTRICAL AND ELECTRONIC ENGINEERING 325
INFORMATION AND COMMUNICATION TECHNOLOGIES AND SERVICES VOLUME: 13 |NUMBER: 4 |2015 |SPECIAL ISSUE
ack ha ocuses on ob aining speci ic sensi i e
in o ma ion (e.g. he a acke knows a bug in he
sys em and he in ends o ake ad an age o ha ).
Unde no mal ci cums ances, he a ack ealized
would be easily de ec able bu wi hin he massi e
DDoS a ack, i is ex emely di icul o iden i y
his a ack. Hence, he a acke has enough ime
o ake ad an age o he bug. I usually akes
se e al days o go h ough all logs o disclose he
hidden a ack. The a ge o hese a acks can be
almos anyone (companies, go e nmen ne wo ks,
media se e s, he banking sec o and end use s).
•Ex o ion - in his case, he ic im mus pay he
a acke ce ain amoun o money unde he h ea
o DDoS a ack.
1.1. S a e o he A
F om he a ailable secu i y epo s ha analyze he
ne wo k a ic, one can ob ain mo e de ailed in o ma-
ion abou DDoS a acks ha ha e been ealized wi hin
a ce ain ime pe iod. Impo an in o ma ion a e he
dis ibu ion o indi idual a acks, du a ion, in ensi y
and a ge o a ack [11], [12], [13], [14]. Based on his
in o ma ion, we can conclude he ollowing ac s:
•The dis ibu ion o DDoS a ack ypes changes
eally quickly in esponse o he p o ec ion im-
plemen ed. Fo example, SynFlood was he mos
widely used a ack ea lie bu nowadays i is e-
placed by DNSFlood because a lo o use s ha e
al eady implemen ed SynFlood p o ec ion.
•Secu i y epo s con i med he balance o DDoS
a acks a ge ed a applica ions and ne wo k in-
as uc u e.
•A acke s use inc easingly mo e sophis ica ed
DDoS a acks ha combine di e en echniques
o DDoS. One example is a la ge UDPFlood com-
bined wi h a slow HTTPFlood [15].
•In ensi y o DDoS a acks is apidly inc easing
[16], [17]. Fo example, he a e age in ensi y o
one DDoS a ack was 3.92 Gbps in he i s quad-
an o 2014, in he second quad an , he a e age
in ensi y was 12.42 Gbps. Hence, we can suppose
he pe manen inc ease o he a ack in ensi y.
One can cas doub s on he de achmen o in o ma-
ion p o ided because hese epo s a e made by p o-
duce s o DDoS p o ec ion. Howe e , we can con i m
he same ac s om in o ma ion p o ided by da a se -
ice p o ide s om he Czech Republic (P o ide s o
da a se ices a e ic ims o DDoS a acks, he e o e,
p o iding co ec da a is in hei own in e es ). In he
Czech Republic, he DDoS a acks demons a ed hei
e ec i eness in 2013. The media se e s (iDNES.cz,
IHNED.cz, Lido ky.cz, Seznam.cz e c.), se e s o mo-
bile ope a o s (T-Mobile, Tele onica O2 e c.) and bank
se e s (CSOB, Kome cni banka, Ceska spo i elna e c.)
we e a ge s o he a acks successi ely. Du ing hese
a acks, end use s could no send and ecei e elec onic
mails, make paymen s in In e ne banking and pay-
men e minals did no wo k. The s a is ics o da a
cen e WEDOS and Ne hos con i m ha he impo -
an h ead lies in inc easing in ensi y o DDoS a acks.
In 2013, hese da a cen e s de ec ed a acks wi h in-
ensi y a ound 3Gbps, a he beginning o 2014, he
a acks had in ensi y o 6Gbps and in he middle o
he yea he a acks had in ensi y o 20 Gbps.
Gene ally, i is eally di icul o de end agains hese
ypes o a acks because hey do no a ge speci ic
ulne abili ies o he sys ems. Academia and indus y
ha e made emendous e o s o de end DDoS a acks
[10], [18]. In he i s s ep, DDoS a acks a e ecogniz-
able and classi iable by de ec ing anomalies in ne wo k
a ic based on machine lea ning [19]. In he second
s ep, he illegi ima e a ic is d opped. A simple ap-
p oach is based on he black and whi e lis s [20]. An
in e es ing me hod ha ies o mi iga e DDoS a acks
by an o ensi e app oach was p esen ed [21]. Tech-
niques based on packe ma king equi e a huge amoun
o packe s o be moni o ed [22], [23]. In ou esea ch,
we ocus on basic de ense echniques ha a e based on
secu e ne wo k in as uc u e [24], [25], [26]. The mos
impo an elemen o he in as uc u e is IPS (In u-
sion P e en ion Sys ems).
On he ma ke , se e al IPS solu ions can be ound
ha de ec and elimina e qui e well he DDoS a acks
on he ne wo k in as uc u e. The ollowing lis shows
he mos known and used solu ions: DDoS p o ec ion
(F5), De enceP o (Radwa e), DDoS p o ec ion (P o-
lexic Technologies), P a ail A ailabili y P o ec ion Sys-
em (ARBOR Ne wo ks) and ADS se ies (NSFOCUS
In o ma ion Technology). Comme cially a ailable so-
lu ions con ain se e al p incipal lacks ha make impos-
sible hei wide applica ion. Main lacks can be sum-
ma ized as ollows:
•High acquisi ion p ice - all comme cial solu ions
men ioned abo e a e e y expensi e. The eco-
nomic cos is he main eason why mos o he
smalle en i ies a e unp o ec ed (Valid o he
Czech Republic). F om a simple calcula ion o he
numbe o DDoS a acks pe yea , he cos o he
IPS de ice, ope a ing cos s, he ime when he de-
ice is ac i e, i ollows ha i is an ine iciency
in es men .
•Impossibili y o he DDoS p o ec ion sha ing -
o hese sys ems, i is no possible o sha e he
DDoS p o ec ion o mo e en i ies, because p o-
duce s ha e know-how and hey p e en sha ing
c
2015 ADVANCES IN ELECTRICAL AND ELECTRONIC ENGINEERING 326
INFORMATION AND COMMUNICATION TECHNOLOGIES AND SERVICES VOLUME: 13 |NUMBER: 4 |2015 |SPECIAL ISSUE
Se e
Se e
Swi ch A ailable ese e HW
esou ces
LACP LACP
1/10 Gbps
1/10 Gbps
.
.
..
.
.
Se e
1/10 Gbps
Swi ch
Powe
managemen
Legi ima e
a ic +DDoS
a acks
Legi ima e
a ic
Fig. 1: Block diag am o he sys em p oposed.
by license (in ac , hese de ices a e no designed
o sha ing).
•P oblem o edundancy solu ion - i is no possi-
ble o ealize edundancy wi hou buying an addi-
ional equipmen .
•Maximum h oughpu limi a ion - his is he c i -
ical disad an age. These comme cial de ices a e
limi ed by he maximum speed o he in e ace
(e.g. 10 Gbps) and he h oughpu canno be in-
c eased linea ly (one can combine mul iple de ices,
bu he p ice is mul iplied). Based on he cu en
s a e, he a e age in ensi y o DDoS a acks ex-
ceeds he speed o 10 Gbps mo e han wo imes.
A modula DDoS p o ec ion sys em ha would
allow o inc ease he il e ing capaci y linea ly is
comple ely missing.
•Comme cial solu ions a e no sui able o da a
cen e s.
Recen ly, many companies such as Incapsula, De-
ense.ne , P olexic DDoS Mi iga ion Se ices, Ve isign
DDoS P o ec ion Se ices, CloudFla e En e p ise,
Nexusgua d ha e o e ed DDoS p o ec ion as a se ice
based on he cloud. The cloud based DDoS p o ec ion
can be less expensi e o ce ain ypes o he clien s
(small/medium companies), ne e heless, he de ec ion
and mi iga ion o DDoS a acks can ake longe due
o he ou ing. The e o e, i is desi able o de elop
DDoS solu ion wi h he ollowing p ope ies: cheap so-
lu ion, possibili y o inc ease he il e ing capaci y lin-
ea ly, sui abili y o da a cen e s, scalable, and easy-
o-manage.
1.2. Ou Con ibu ion
This sho pape epo s some p elimina y esul s and
he main ideas o ou ongoing p ojec . The main goal
o ou p ojec is o p opose and implemen a scalable
so wa e DDoS p o ec ion ha elimina es he lacks o
he comme cially a ailable solu ions. Ou esea ch and
key obse a ions a e s ongly ocused on applicabil-
i y in da a cen e s because he esea ch is conduc ed
in coope a ion wi h he comme cial company Ne hos .
The company ope a es da a cen e wi h mo e han 800
se e s and 2.500 VPS (Vi ual P i a e Se e ). Ou
main in en ion is o ealize an an i-DDoS sys em whe e
i is possible o inc ease h oughpu ( il e ing capaci y)
linea ly and acquisi ion cos s a e eally small. A he
beginning o he a icle, we ha e p esen ed a c i ical
analysis o he exis ing IPS sys ems and ou mo i a-
ion. Based on he main ac s, we p opose ou DDoS
solu ion ha elimina es hese lacks. We illus a e he
main ideas using he main unc ional componen s o
he sys em.
2. Sys em P oposal
The key obse a ion o sys em p oposed is based on he
ee a ailabili y o edundan ha dwa e esou ces ha
can be e ec i ely used o elimina e ( il e ) DDoS a -
acks. Da a cen e s ha e o mode nize hei ha dwa e
esou ces p ac ically e e y yea , he e o e hey ha e
plen y o ese e ha dwa e ha has a su icien com-
pu ing powe . Fo example, he company Ne hos has
ese e ha dwa e in he p ice o 260 000 $ a p esen .
The main idea is o de elop a DDoS de ense sys em
in he o m o po able so wa e image ha can be
ins alled on he ese e ha dwa e esou ces (se e s).
Du ing a DDoS a ack, hese se e s will be used as
c
2015 ADVANCES IN ELECTRICAL AND ELECTRONIC ENGINEERING 327
INFORMATION AND COMMUNICATION TECHNOLOGIES AND SERVICES VOLUME: 13 |NUMBER: 4 |2015 |SPECIAL ISSUE
SynFlood UDPFlood DNS Flood
HTTP
Flood
RST Flood
ICMP
Flood Land
A ack and o he s
Indi idual DDoS il e s
Basic
modules
Ex ended
modules
Fig. 2: Block diag am o he DDoS il e s implemen ed.
il e s o his DDoS a ack. The block diag am o he
sys em p oposed is depic ed in Fig. 1.
Rese e se e s ha con ain he ins alled image o
he de ense sys em, will be connec ed o he swi ch (o
b idge, i will be decided la e based on benchma k es
ealized du ing he p ojec ) using 1Gbps o 10 Gbps
po s. By de aul , he de ense sys em p oposed (a il e
o DDoS) is u ned o and i consumes no ene gy. Du -
ing he DDoS a ack, he equi ed numbe o se e s
will be connec ed using he powe managemen sys em
and he equi ed amoun o a ic will be il e ed using
he LACP (Link Agg ega ion Con ol P o ocol). Fo
example, we connec wo se e s using 10 Gbps po s,
he e o e he p oposed sys em will be able o il e le-
gi ima e a ic wi hin he DDoS a ack ha exceeds
12 Gbps. A e DDoS e mina ion, he se e s will be
u ned o in o de o sa e ope a ing cos s o special
so wa e modules will be ac i a ed o accele a e p oxy,
o pe o m secu i y es s o o un a i us scan.
The de ense sys em p oposed includes il e ing mod-
ules specialized ha a e a ge ed a he speci ic ypes
o DDoS a acks. This modula i y allows easy and as
modi ica ion, eac ion and supplemen a ion. The mod-
ula scheme also allows o elimina e he di e en com-
bina ion o DDoS a acks in a simple manne . We as-
sume ha he sys em will always con ain basic il e s
such as SynFlood, UDPFlood, HTTPFlood and DNS-
Flood co esponding wi h he mos commonly used
DDoS a acks. Fu he mo e, he sys em will con ain
il e ing modules ex ended o o he ypes o DDoS a -
acks (we assume ICMPFlood, FloodRST e c.) ha
will be g adually implemen ed. Block diag am o he
indi idual il e ing module is depic ed in Fig. 2.
The en opy a ic models, ime se ies analysis and
s a ic analysis o da a a ic a e included in ou e-
sea ch o de ec he DDoS a acks. We do no conside
he beha io al analysis me hods because we in end
o a oid he p oblems associa ed wi h lea ning phase
(necessa y lea ning, inaccu acy pa e ns, e-lea ning i
ne wo k con igu a ion is changed, e c.). The indi id-
ual il e s a e implemen ed in a o m o special g ids
ha e ec i ely elimina e speci ic DDoS a acks (g ids
espond o speci ic p o ocol pa ame e s o condi ions
acco ding o he p o ocols RFC (Reques Fo Com-
men s)). In ac , his implemen a ion ep esen s an
imp o ed s a e analysis o indi idual p o ocols.
The p oposed modula sys em in he o m o he
po able image is based on i ualiza ion, he e o e i
is possible o in ol e all a ailable compu ing capaci y
o il e DDoS a acks. Theo e ically, one can il e any
amoun o he a ic depending on he a ailable com-
pu a ional esou ces. The key ad an age lies in he
linea inc ease o il e ing capaci y in esponse o he
cu en s a e o he DDoS a acks. This is he main ad-
an age in compa ison wi h comme cial sys ems. The
scalable de ense sys em educes he cos s by using own
ha dwa e, i.e. he sys em ep esen s a mo e con enien
solu ion in e ms o in es men and liquidi y o a la ge
numbe o end use s. We summa ize he main ad an-
ages o he sys em p oposed in he ollowing poin s:
•The sys em allows linea inc easing o he il e ing
capaci y.
•The so wa e solu ion is sui able o da a cen-
e s (sha ed DDoS p o ec ion has in luence on big
numbe o end use s).
•The sys em is implemen ed on se e al indi iduals
nodes, he e o e in case o ailu e, one will lose
only one pa o he il e ing capaci y ( edundan
solu ion).
•E ec i e usage o a ailable ha dwa e esou ces.
•Low p ice.
•Modula i y enables quick eac ion o new DDoS
a acks and o p o ec agains combina ion o a -
acks.
3. Conclusion
This pape epo s some p elimina y esul s and he
main ideas o ou ongoing p ojec , ha aims o de elop
a scalable DDoS mi iga ion sys em, which is sui able
o da a cen e s. The main idea lies in u iliza ion o
edundan ha dwa e esou ces o elimina e he DDoS
a acks. We belie e ha he sys em p oposed eaches
su icien il e ing capaci y by combina ion o so wa e
and ha dwa e o mee he needs o da a cen e s. The
main ad an ages o he sys em a e he linea inc easing
o he il e ing capaci y, sha ing o DDoS p o ec ion
and low p ice.
Fu u e wo k o ou esea ch is he implemen a ion
and es ing o he sys em p oposed. Fi s ly, we wan o
ocus on benchma k es ing o il e ing capaci y. Sub-
sequen ly, we will ocus on he esea ch and es ing o
indi idual il e ing modules.
c
2015 ADVANCES IN ELECTRICAL AND ELECTRONIC ENGINEERING 328
INFORMATION AND COMMUNICATION TECHNOLOGIES AND SERVICES VOLUME: 13 |NUMBER: 4 |2015 |SPECIAL ISSUE
Acknowledgmen
Resea ch desc ibed in his pape was inanced by he
Na ional Sus ainabili y P og am unde g an LO1401.
Fo he esea ch, in as uc u e o he SIX Cen e was
used.
Re e ences
[1] SRIVASTAVA, A., B. B. GUPTA, A. TYAGI, A.
SHARMA and A. MISHRA. Ad ances in Pa allel
Dis ibu ed Compu ing - A ecen su ey on DDoS
a acks and de ense mechanisms. Be lin: Sp inge ,
2011. ISBN 978-3-642-24036-2.
[2] WANG, H., D. ZHANG and K. G. SHIN.
De ec ing SYN looding a acks. In: P oceed-
ings o IEEE Twen y-Fi s Annual Join Con-
e ence o he IEEE Compu e and Com-
munica ions Socie ies (INFOCOM 2002). New
Yo k: IEEE, 2002, pp. 1530–1539. ISBN 0-7803-
7476-2. DOI: 10.1109/INFCOM.2002.1019404.
[3] KIM, M. S., H. J. KONG, S. C. HONG, S. H.
CHUNG and J. W. HONG. A low-based me hod
o abno mal ne wo k a ic de ec ion. In: Ne -
wo k Ope a ions and Managemen Symposium,
2004. Seoul: IEEE, 2004, pp. 599–612. ISBN 0-
7803-8230-7. DOI: 10.1109/NOMS.2004.1317747.
[4] LAU, F., S. H. RUBIN, M. H. SMITH and
L. TRAJAKOVIC. Dis ibu ed denial o se -
ice a acks. In: IEEE In e na ional Con e -
ence on Sys ems, Man, and Cybe ne ics, 2000.
Nash ille: IEEE, 2000, pp. 2275–2280. ISBN 0-
7803-6583-6. DOI: 10.1109/ICSMC.2000.886455.
[5] SOMMER, R., D. BALZAROTTI and G.
MAIER. Recen Ad ances in In usion De ec ion.
Be lin: Sp inge , 2011, pp. 161–180. ISBN 978-3-
642-23644-0.
[6] LIMWIWATKUL, L. and A. RUNGSAWANG.
Dis ibu ed denial o se ice de ec ion using
TCP/IP heade and a ic measu emen analysis.
In: IEEE In e na ional Symposium on Commu-
nica ions and In o ma ion Technologies (ISCIT
2004). Sappo o: IEEE, 2014, pp. 605–610. ISBN 0-
7803-8593-4. DOI: 10.1109/ISCIT.2004.1412917.
[7] AKBAR, M. A., Z. TARIQ and M. FAROOQ.
A compa a i e s udy o anomaly de ec ion algo-
i hms o de ec ion o SIP looding. In: 2nd In e -
na ional Con e ence on In e ne Mul imedia Se -
ices A chi ec u e and Applica ions (IMS 2008).
Bangalo e: IEEE, 2008, pp. 1–6. ISBN 978-1-4244-
2684-3. DOI: 10.1109/IMSAA.2008.4753934.
[8] CHELSEA, A. Gene a ed anomaly pa e n o
HTTP lood p o ec ion. US Pa en 7617170.
Pa en ed 2009.
[9] MIRKOVIC, J. and P. REIHER. A axonomy
o DDoS a ack and DDoS de ense. ACM SIG-
COMM Compu e Communica ion Re iew. 2004,
ol. 34, no. 2, pp. 39–53. ISSN 0146-4833.
DOI: 10.1145/997150.997156.
[10] PENG, T., C. LECKIE and K. RAMAMOHA-
NARAO. Su ey o ne wo k-based de ense mech-
anisms coun e ing he DoS and DDoS p ob-
lems. ACM Compu ing Su eys (CSUR). 2007,
ol. 39, no. 1, pp. 1–42. ISSN 0360-0300.
DOI: 10.1145/1216370.1216373.
[11] Global applica ion & ne wo k secu i y epo
2013. RADWARE. 2013.
[12] BAO, X. and H. HONG. NSFOCUS DDoS h ea
epo 2013. NSFOCUS In o ma ion Technology.
2013.
[13] P olexic qua e ly global DDoS A ack Repo
Q1-Q4. AKAMAI. 2013.
[14] Global applica ion & ne wo k secu i y epo
2014. RADWARE. 2014.
[15] HANSEN, R. Slowlo is HTTP DoS. Hack-
e s.o g [online]. 2014. A ailable a : h p://ha.
cke s.o g/slowlo is/.
[16] Dis ibu ed denial o se ice ends epo .
VERISIGN. 2014.
[17] PLXse ’s Q4 2014 s a e o he in e ne –Secu i y
Repo . AKAMAI. 2014.
[18] ZARGAR, S. T., J. JOSHI and D. TIPPER.
A Su ey o De ense Mechanisms Agains Dis-
ibu ed Denial o Se ice (DDoS) Flooding A -
acks. IEEE Communica ions Su eys &Tu o i-
als. 2004, ol. 15, no. 4, pp. 2046–2069. ISSN 1553-
877X. DOI: 10.1109/SURV.2013.031413.00127.
[19] JALILI, R., F. IMANI-MEHR, M. AMINI and
H. R. SHAHRIARI. De ec ion o Dis ibu ed De-
nial o Se ice A acks Using S a is ical P e-
p ocesso and Unsupe ised Neu al Ne wo ks. In-
o ma ion Secu i y P ac ice and Expe ience. 2005,
ol. 3439, iss. 1, pp. 192–203. ISSN 0302-9743.
DOI: 10.1007/978-3-540-31979-5_17.
[20] KANG, S. H., K. Y. PARK, S. G. YOO
and J. KIM. DDoS a oidance s a egy o
se ice a ailabili y. Clus e Compu ing. 2013,
ol. 16, no. 2, pp. 241–248. ISSN 1386-7857.
DOI: 10.1007/s10586-011-0185-4.
c
2015 ADVANCES IN ELECTRICAL AND ELECTRONIC ENGINEERING 329

INFORMATION AND COMMUNICATION TECHNOLOGIES AND SERVICES VOLUME: 13 |NUMBER: 4 |2015 |SPECIAL ISSUE
[21] WALFISH, M., M. VUTUKURU, H. BAL-
AKRISHNAN, D. KARGER and S. SHENKER.
DDoS de ense by o ense. In: P oceedings o
he 2006 con e ence on Applica ions, echnolo-
gies, a chi ec u es, and p o ocols o compu e
communica ions (SIGCOMM 2006). New Yo k:
ACM, 2006, pp. 303–314. ISBN 1-59593-308-5.
DOI: 10.1145/1159913.1159948.
[22] BELENKY, A. and N. ANSARI. On de e min-
is ic packe ma king. Compu e Ne wo ks. 2007,
ol. 51, no. 10, pp. 2677–2700. ISSN 1389-1286.
DOI: 10.1016/j.comne .2006.11.020.
[23] SEVAGE, S., D. WETHERALL, A. KARLIN and
T. ANDERSON. P ac ical ne wo k suppo o IP
aceback. ACM SIGCOMM Compu e Commu-
nica ion Re iew. 2000, ol. 30, no. 4, pp. 295–306.
ISSN 0146-4833. DOI: 10.1145/347057.347560.
[24] PATEL, C. M. and V. BORISAGAR. Su ey On
Taxonomy O Ddos A acks Wi h Impac And
Mi iga ion Techniques. In e na ional Jou nal o
Enginee ing Resea ch &Technology. 2012, ol. 1,
no. 9, pp. 1–8. ISSN 2278-0181.
[25] JAIN, A. and A. K. SINGH. Dis ibu ed denial o
se ice (DDoS) a acks-classi ica ion and implica-
ions. Jou nal o In o ma ion &Ope a ions Man-
agemen . 2012, ol. 3, no. 1, pp. 136. ISSN 0976-
7754.
[26] LOUKAS, G. and G. OEKE. P o ec ion agains
denial o se ice a acks: A su ey. The Com-
pu e Jou nal. 2010, ol. 53, no. 7, pp. 1020–1037.
ISSN 1020-1037.
Abou Au ho s
Zdenek MARTINASEK Recei ed M.Sc. (Ing.) a
he Depa men o Telecommunica ions a he Facul y
o Elec ical Enginee ing and Communica ion a B no
Uni e si y o Technology in 2008. He ecei ed Ph.D.
a he same Depa men . He also helps o co e
pedagogically Mas e ’s p og am cou se. The a ea
o his p o essional in e es s is c yp og aphy, powe
analysis, senso s and mode n da a communica ion.
c
2015 ADVANCES IN ELECTRICAL AND ELECTRONIC ENGINEERING 330