INFORMATION AND COMMUNICATION TECHNOLOGIES AND SERVICES VOLUME: 13 |NUMBER: 4 |2015 |SPECIAL ISSUE
Scalable DDoS Mi iga ion Sys em o Da a Cen e s
Zdenek MARTINASEK
Depa men o Telecommunica ions, Facul y o Elec ical Enginee ing and Communica ion,
B no Uni e si y o Technology, Technicka 12, 616 00 B no, Czech epublic
[email p o ec ed]
DOI: 10.15598/aeee. 13i4.1531
Abs ac . Dis ibu ed Denial o Se ice a acks
(DDoS) ha e been used by a acke s o o e wo
decades because o hei e ec i eness. This ype o he
cybe -a ack is one o he mos des uc i e a acks in
he In e ne . In ecen yea s, he in ensi y o DDoS
a acks has been apidly inc easing and he a acke s
combine mo e o en di e en echniques o DDoS o by-
pass he p o ec ion. The e o e, he main goal o ou e-
sea ch is o p opose a DDoS solu ion ha allows o in-
c ease he il e ing capaci y linea ly and allows o p o-
ec agains he combina ion o a acks. The main idea
is o de elop he DDoS de ense sys em in he o m o
a po able so wa e image ha can be ins alled on he
ese e ha dwa e capaci ies. Du ing a DDoS a ack,
hese se e s will be used as il e s o his DDoS a -
ack. Ou solu ion is sui able o da a cen e s and elim-
ina es some lacks o comme cial solu ions. The sys em
employs modula DDoS il e s in he o m o special
g ids con aining speci ic p o ocol pa ame e s and con-
di ions.
Keywo ds
Da a cen e , DDoS, p o ec ion.
1. In oduc ion
Nowadays, he isk o cybe -a acks ha a e aimed a
go e nmen , companies, news media o end use s ep-
esen s a eal h ea . Acco ding o he s udies ealized
annually, he mos commonly used echniques o cybe -
a acks a e DoS (Denial o Se ice) and SQL (S uc-
u ed Que y Language) injec ion (I is a s a is ic o
ac ually ealized a acks). DoS a acks can be simply
di ided in o wo basic ypes [1]: Flooding a acks and
Logical a acks. In Flooding DoS a acks, an a acke
sends a la ge amoun o a ic o consume CPU (Cen-
al P ocessing Uni ) o he bandwid h o he ic im.
The DoS a ack consumes he esou ces o he ic im’s
se e o ne wo k in o de o deg ade a pe o mance
o cause a se e c ash. Flooding a acks ake ad an-
age o he weaknesses o he communica ion p o ocols
such as TCP (T ansmission Con ol P o ocol) [2], [3],
UDP (Use Da ag am P o ocol) [4], [5], ICMP (In e -
ne Con ol Message P o ocol)[6], FTP (File T ans e
P o ocol) [2], SIP (Session Ini ia ion P o ocol) [7] o
HTTP (Hype ex T ans e P o ocol) [8]. Logical a -
acks use weaknesses in applica ions o so wa e used
a he ic im’s side. The a acke sends only a ew
messages ha abuse he weaknesses o he so wa e in
o de o disable o c ash he a ge machine. The DoS
a ack is usually pe o med by a ne wo k node (e.g. a
pe sonal compu e ) seized by he a acke [1]. These
ne wo k nodes a e called zombies o bo ne s and hey
a e no comple ely unde he con ol o he a acke .
I causes ha he a ack consis s o la ge quan i ies o
eques s (usually hund eds o housands), wha can be
ealized om all o e he wo ld. The a acke c ea es
a necessa y in as uc u e o bo ne s simply by using
T ojan ho ses o o he malwa e, ha a e unning on
he in ec ed ne wo k nodes. Dis ibu ed Denial o Se -
ice a acks a e pe o med by mul iple nodes. Cu -
en ly, he in as uc u e o bo ne s is ge ing bigge
and eady o a ack any ime. Mo e de ails abou DDoS
a acks can be ound in su ey pape s [9], [10].
In p ac ice, DDoS a acks ha e di e en use cases
and a ge s. We summa ize hese obse a ions in he
ollowing poin s:
•Denial o Se ice - i ep esen s a classic usage
o DDoS a acks. The compe ing companies a e
usually he a ge in his use case and he a acke
wan s o cause la ge inancial losses and impai he
company’s epu a ion. Go e nmen ne wo ks and
media se e s a e ano he ypical a ge o hese
a acks.
•Masking o cybe -a acks - in his case, he a -
acke uses a DDoS a ack o mask he “ ue” a -
c
2015 ADVANCES IN ELECTRICAL AND ELECTRONIC ENGINEERING 325
INFORMATION AND COMMUNICATION TECHNOLOGIES AND SERVICES VOLUME: 13 |NUMBER: 4 |2015 |SPECIAL ISSUE
ack ha ocuses on ob aining speci ic sensi i e
in o ma ion (e.g. he a acke knows a bug in he
sys em and he in ends o ake ad an age o ha ).
Unde no mal ci cums ances, he a ack ealized
would be easily de ec able bu wi hin he massi e
DDoS a ack, i is ex emely di icul o iden i y
his a ack. Hence, he a acke has enough ime
o ake ad an age o he bug. I usually akes
se e al days o go h ough all logs o disclose he
hidden a ack. The a ge o hese a acks can be
almos anyone (companies, go e nmen ne wo ks,
media se e s, he banking sec o and end use s).
•Ex o ion - in his case, he ic im mus pay he
a acke ce ain amoun o money unde he h ea
o DDoS a ack.
1.1. S a e o he A
F om he a ailable secu i y epo s ha analyze he
ne wo k a ic, one can ob ain mo e de ailed in o ma-
ion abou DDoS a acks ha ha e been ealized wi hin
a ce ain ime pe iod. Impo an in o ma ion a e he
dis ibu ion o indi idual a acks, du a ion, in ensi y
and a ge o a ack [11], [12], [13], [14]. Based on his
in o ma ion, we can conclude he ollowing ac s:
•The dis ibu ion o DDoS a ack ypes changes
eally quickly in esponse o he p o ec ion im-
plemen ed. Fo example, SynFlood was he mos
widely used a ack ea lie bu nowadays i is e-
placed by DNSFlood because a lo o use s ha e
al eady implemen ed SynFlood p o ec ion.
•Secu i y epo s con i med he balance o DDoS
a acks a ge ed a applica ions and ne wo k in-
as uc u e.
•A acke s use inc easingly mo e sophis ica ed
DDoS a acks ha combine di e en echniques
o DDoS. One example is a la ge UDPFlood com-
bined wi h a slow HTTPFlood [15].
•In ensi y o DDoS a acks is apidly inc easing
[16], [17]. Fo example, he a e age in ensi y o
one DDoS a ack was 3.92 Gbps in he i s quad-
an o 2014, in he second quad an , he a e age
in ensi y was 12.42 Gbps. Hence, we can suppose
he pe manen inc ease o he a ack in ensi y.
One can cas doub s on he de achmen o in o ma-
ion p o ided because hese epo s a e made by p o-
duce s o DDoS p o ec ion. Howe e , we can con i m
he same ac s om in o ma ion p o ided by da a se -
ice p o ide s om he Czech Republic (P o ide s o
da a se ices a e ic ims o DDoS a acks, he e o e,
p o iding co ec da a is in hei own in e es ). In he
Czech Republic, he DDoS a acks demons a ed hei
e ec i eness in 2013. The media se e s (iDNES.cz,
IHNED.cz, Lido ky.cz, Seznam.cz e c.), se e s o mo-
bile ope a o s (T-Mobile, Tele onica O2 e c.) and bank
se e s (CSOB, Kome cni banka, Ceska spo i elna e c.)
we e a ge s o he a acks successi ely. Du ing hese
a acks, end use s could no send and ecei e elec onic
mails, make paymen s in In e ne banking and pay-
men e minals did no wo k. The s a is ics o da a
cen e WEDOS and Ne hos con i m ha he impo -
an h ead lies in inc easing in ensi y o DDoS a acks.
In 2013, hese da a cen e s de ec ed a acks wi h in-
ensi y a ound 3Gbps, a he beginning o 2014, he
a acks had in ensi y o 6Gbps and in he middle o
he yea he a acks had in ensi y o 20 Gbps.
Gene ally, i is eally di icul o de end agains hese
ypes o a acks because hey do no a ge speci ic
ulne abili ies o he sys ems. Academia and indus y
ha e made emendous e o s o de end DDoS a acks
[10], [18]. In he i s s ep, DDoS a acks a e ecogniz-
able and classi iable by de ec ing anomalies in ne wo k
a ic based on machine lea ning [19]. In he second
s ep, he illegi ima e a ic is d opped. A simple ap-
p oach is based on he black and whi e lis s [20]. An
in e es ing me hod ha ies o mi iga e DDoS a acks
by an o ensi e app oach was p esen ed [21]. Tech-
niques based on packe ma king equi e a huge amoun
o packe s o be moni o ed [22], [23]. In ou esea ch,
we ocus on basic de ense echniques ha a e based on
secu e ne wo k in as uc u e [24], [25], [26]. The mos
impo an elemen o he in as uc u e is IPS (In u-
sion P e en ion Sys ems).
On he ma ke , se e al IPS solu ions can be ound
ha de ec and elimina e qui e well he DDoS a acks
on he ne wo k in as uc u e. The ollowing lis shows
he mos known and used solu ions: DDoS p o ec ion
(F5), De enceP o (Radwa e), DDoS p o ec ion (P o-
lexic Technologies), P a ail A ailabili y P o ec ion Sys-
em (ARBOR Ne wo ks) and ADS se ies (NSFOCUS
In o ma ion Technology). Comme cially a ailable so-
lu ions con ain se e al p incipal lacks ha make impos-
sible hei wide applica ion. Main lacks can be sum-
ma ized as ollows:
•High acquisi ion p ice - all comme cial solu ions
men ioned abo e a e e y expensi e. The eco-
nomic cos is he main eason why mos o he
smalle en i ies a e unp o ec ed (Valid o he
Czech Republic). F om a simple calcula ion o he
numbe o DDoS a acks pe yea , he cos o he
IPS de ice, ope a ing cos s, he ime when he de-
ice is ac i e, i ollows ha i is an ine iciency
in es men .
•Impossibili y o he DDoS p o ec ion sha ing -
o hese sys ems, i is no possible o sha e he
DDoS p o ec ion o mo e en i ies, because p o-
duce s ha e know-how and hey p e en sha ing
c
2015 ADVANCES IN ELECTRICAL AND ELECTRONIC ENGINEERING 326
INFORMATION AND COMMUNICATION TECHNOLOGIES AND SERVICES VOLUME: 13 |NUMBER: 4 |2015 |SPECIAL ISSUE
Se e
Se e
Swi ch A ailable ese e HW
esou ces
LACP LACP
1/10 Gbps
1/10 Gbps
.
.
..
.
.
Se e
1/10 Gbps
Swi ch
Powe
managemen
Legi ima e
a ic +DDoS
a acks
Legi ima e
a ic
Fig. 1: Block diag am o he sys em p oposed.
by license (in ac , hese de ices a e no designed
o sha ing).
•P oblem o edundancy solu ion - i is no possi-
ble o ealize edundancy wi hou buying an addi-
ional equipmen .
•Maximum h oughpu limi a ion - his is he c i -
ical disad an age. These comme cial de ices a e
limi ed by he maximum speed o he in e ace
(e.g. 10 Gbps) and he h oughpu canno be in-
c eased linea ly (one can combine mul iple de ices,
bu he p ice is mul iplied). Based on he cu en
s a e, he a e age in ensi y o DDoS a acks ex-
ceeds he speed o 10 Gbps mo e han wo imes.
A modula DDoS p o ec ion sys em ha would
allow o inc ease he il e ing capaci y linea ly is
comple ely missing.
•Comme cial solu ions a e no sui able o da a
cen e s.
Recen ly, many companies such as Incapsula, De-
ense.ne , P olexic DDoS Mi iga ion Se ices, Ve isign
DDoS P o ec ion Se ices, CloudFla e En e p ise,
Nexusgua d ha e o e ed DDoS p o ec ion as a se ice
based on he cloud. The cloud based DDoS p o ec ion
can be less expensi e o ce ain ypes o he clien s
(small/medium companies), ne e heless, he de ec ion
and mi iga ion o DDoS a acks can ake longe due
o he ou ing. The e o e, i is desi able o de elop
DDoS solu ion wi h he ollowing p ope ies: cheap so-
lu ion, possibili y o inc ease he il e ing capaci y lin-
ea ly, sui abili y o da a cen e s, scalable, and easy-
o-manage.
1.2. Ou Con ibu ion
This sho pape epo s some p elimina y esul s and
he main ideas o ou ongoing p ojec . The main goal
o ou p ojec is o p opose and implemen a scalable
so wa e DDoS p o ec ion ha elimina es he lacks o
he comme cially a ailable solu ions. Ou esea ch and
key obse a ions a e s ongly ocused on applicabil-
i y in da a cen e s because he esea ch is conduc ed
in coope a ion wi h he comme cial company Ne hos .
The company ope a es da a cen e wi h mo e han 800
se e s and 2.500 VPS (Vi ual P i a e Se e ). Ou
main in en ion is o ealize an an i-DDoS sys em whe e
i is possible o inc ease h oughpu ( il e ing capaci y)
linea ly and acquisi ion cos s a e eally small. A he
beginning o he a icle, we ha e p esen ed a c i ical
analysis o he exis ing IPS sys ems and ou mo i a-
ion. Based on he main ac s, we p opose ou DDoS
solu ion ha elimina es hese lacks. We illus a e he
main ideas using he main unc ional componen s o
he sys em.
2. Sys em P oposal
The key obse a ion o sys em p oposed is based on he
ee a ailabili y o edundan ha dwa e esou ces ha
can be e ec i ely used o elimina e ( il e ) DDoS a -
acks. Da a cen e s ha e o mode nize hei ha dwa e
esou ces p ac ically e e y yea , he e o e hey ha e
plen y o ese e ha dwa e ha has a su icien com-
pu ing powe . Fo example, he company Ne hos has
ese e ha dwa e in he p ice o 260 000 $ a p esen .
The main idea is o de elop a DDoS de ense sys em
in he o m o po able so wa e image ha can be
ins alled on he ese e ha dwa e esou ces (se e s).
Du ing a DDoS a ack, hese se e s will be used as
c
2015 ADVANCES IN ELECTRICAL AND ELECTRONIC ENGINEERING 327
INFORMATION AND COMMUNICATION TECHNOLOGIES AND SERVICES VOLUME: 13 |NUMBER: 4 |2015 |SPECIAL ISSUE
SynFlood UDPFlood DNS Flood
HTTP
Flood
RST Flood
ICMP
Flood Land
A ack and o he s
Indi idual DDoS il e s
Basic
modules
Ex ended
modules
Fig. 2: Block diag am o he DDoS il e s implemen ed.
il e s o his DDoS a ack. The block diag am o he
sys em p oposed is depic ed in Fig. 1.
Rese e se e s ha con ain he ins alled image o
he de ense sys em, will be connec ed o he swi ch (o
b idge, i will be decided la e based on benchma k es
ealized du ing he p ojec ) using 1Gbps o 10 Gbps
po s. By de aul , he de ense sys em p oposed (a il e
o DDoS) is u ned o and i consumes no ene gy. Du -
ing he DDoS a ack, he equi ed numbe o se e s
will be connec ed using he powe managemen sys em
and he equi ed amoun o a ic will be il e ed using
he LACP (Link Agg ega ion Con ol P o ocol). Fo
example, we connec wo se e s using 10 Gbps po s,
he e o e he p oposed sys em will be able o il e le-
gi ima e a ic wi hin he DDoS a ack ha exceeds
12 Gbps. A e DDoS e mina ion, he se e s will be
u ned o in o de o sa e ope a ing cos s o special
so wa e modules will be ac i a ed o accele a e p oxy,
o pe o m secu i y es s o o un a i us scan.
The de ense sys em p oposed includes il e ing mod-
ules specialized ha a e a ge ed a he speci ic ypes
o DDoS a acks. This modula i y allows easy and as
modi ica ion, eac ion and supplemen a ion. The mod-
ula scheme also allows o elimina e he di e en com-
bina ion o DDoS a acks in a simple manne . We as-
sume ha he sys em will always con ain basic il e s
such as SynFlood, UDPFlood, HTTPFlood and DNS-
Flood co esponding wi h he mos commonly used
DDoS a acks. Fu he mo e, he sys em will con ain
il e ing modules ex ended o o he ypes o DDoS a -
acks (we assume ICMPFlood, FloodRST e c.) ha
will be g adually implemen ed. Block diag am o he
indi idual il e ing module is depic ed in Fig. 2.
The en opy a ic models, ime se ies analysis and
s a ic analysis o da a a ic a e included in ou e-
sea ch o de ec he DDoS a acks. We do no conside
he beha io al analysis me hods because we in end
o a oid he p oblems associa ed wi h lea ning phase
(necessa y lea ning, inaccu acy pa e ns, e-lea ning i
ne wo k con igu a ion is changed, e c.). The indi id-
ual il e s a e implemen ed in a o m o special g ids
ha e ec i ely elimina e speci ic DDoS a acks (g ids
espond o speci ic p o ocol pa ame e s o condi ions
acco ding o he p o ocols RFC (Reques Fo Com-
men s)). In ac , his implemen a ion ep esen s an
imp o ed s a e analysis o indi idual p o ocols.
The p oposed modula sys em in he o m o he
po able image is based on i ualiza ion, he e o e i
is possible o in ol e all a ailable compu ing capaci y
o il e DDoS a acks. Theo e ically, one can il e any
amoun o he a ic depending on he a ailable com-
pu a ional esou ces. The key ad an age lies in he
linea inc ease o il e ing capaci y in esponse o he
cu en s a e o he DDoS a acks. This is he main ad-
an age in compa ison wi h comme cial sys ems. The
scalable de ense sys em educes he cos s by using own
ha dwa e, i.e. he sys em ep esen s a mo e con enien
solu ion in e ms o in es men and liquidi y o a la ge
numbe o end use s. We summa ize he main ad an-
ages o he sys em p oposed in he ollowing poin s:
•The sys em allows linea inc easing o he il e ing
capaci y.
•The so wa e solu ion is sui able o da a cen-
e s (sha ed DDoS p o ec ion has in luence on big
numbe o end use s).
•The sys em is implemen ed on se e al indi iduals
nodes, he e o e in case o ailu e, one will lose
only one pa o he il e ing capaci y ( edundan
solu ion).
•E ec i e usage o a ailable ha dwa e esou ces.
•Low p ice.
•Modula i y enables quick eac ion o new DDoS
a acks and o p o ec agains combina ion o a -
acks.
3. Conclusion
This pape epo s some p elimina y esul s and he
main ideas o ou ongoing p ojec , ha aims o de elop
a scalable DDoS mi iga ion sys em, which is sui able
o da a cen e s. The main idea lies in u iliza ion o
edundan ha dwa e esou ces o elimina e he DDoS
a acks. We belie e ha he sys em p oposed eaches
su icien il e ing capaci y by combina ion o so wa e
and ha dwa e o mee he needs o da a cen e s. The
main ad an ages o he sys em a e he linea inc easing
o he il e ing capaci y, sha ing o DDoS p o ec ion
and low p ice.
Fu u e wo k o ou esea ch is he implemen a ion
and es ing o he sys em p oposed. Fi s ly, we wan o
ocus on benchma k es ing o il e ing capaci y. Sub-
sequen ly, we will ocus on he esea ch and es ing o
indi idual il e ing modules.
c
2015 ADVANCES IN ELECTRICAL AND ELECTRONIC ENGINEERING 328
INFORMATION AND COMMUNICATION TECHNOLOGIES AND SERVICES VOLUME: 13 |NUMBER: 4 |2015 |SPECIAL ISSUE
Acknowledgmen
Resea ch desc ibed in his pape was inanced by he
Na ional Sus ainabili y P og am unde g an LO1401.
Fo he esea ch, in as uc u e o he SIX Cen e was
used.
Re e ences
[1] SRIVASTAVA, A., B. B. GUPTA, A. TYAGI, A.
SHARMA and A. MISHRA. Ad ances in Pa allel
Dis ibu ed Compu ing - A ecen su ey on DDoS
a acks and de ense mechanisms. Be lin: Sp inge ,
2011. ISBN 978-3-642-24036-2.
[2] WANG, H., D. ZHANG and K. G. SHIN.
De ec ing SYN looding a acks. In: P oceed-
ings o IEEE Twen y-Fi s Annual Join Con-
e ence o he IEEE Compu e and Com-
munica ions Socie ies (INFOCOM 2002). New
Yo k: IEEE, 2002, pp. 1530–1539. ISBN 0-7803-
7476-2. DOI: 10.1109/INFCOM.2002.1019404.
[3] KIM, M. S., H. J. KONG, S. C. HONG, S. H.
CHUNG and J. W. HONG. A low-based me hod
o abno mal ne wo k a ic de ec ion. In: Ne -
wo k Ope a ions and Managemen Symposium,
2004. Seoul: IEEE, 2004, pp. 599–612. ISBN 0-
7803-8230-7. DOI: 10.1109/NOMS.2004.1317747.
[4] LAU, F., S. H. RUBIN, M. H. SMITH and
L. TRAJAKOVIC. Dis ibu ed denial o se -
ice a acks. In: IEEE In e na ional Con e -
ence on Sys ems, Man, and Cybe ne ics, 2000.
Nash ille: IEEE, 2000, pp. 2275–2280. ISBN 0-
7803-6583-6. DOI: 10.1109/ICSMC.2000.886455.
[5] SOMMER, R., D. BALZAROTTI and G.
MAIER. Recen Ad ances in In usion De ec ion.
Be lin: Sp inge , 2011, pp. 161–180. ISBN 978-3-
642-23644-0.
[6] LIMWIWATKUL, L. and A. RUNGSAWANG.
Dis ibu ed denial o se ice de ec ion using
TCP/IP heade and a ic measu emen analysis.
In: IEEE In e na ional Symposium on Commu-
nica ions and In o ma ion Technologies (ISCIT
2004). Sappo o: IEEE, 2014, pp. 605–610. ISBN 0-
7803-8593-4. DOI: 10.1109/ISCIT.2004.1412917.
[7] AKBAR, M. A., Z. TARIQ and M. FAROOQ.
A compa a i e s udy o anomaly de ec ion algo-
i hms o de ec ion o SIP looding. In: 2nd In e -
na ional Con e ence on In e ne Mul imedia Se -
ices A chi ec u e and Applica ions (IMS 2008).
Bangalo e: IEEE, 2008, pp. 1–6. ISBN 978-1-4244-
2684-3. DOI: 10.1109/IMSAA.2008.4753934.
[8] CHELSEA, A. Gene a ed anomaly pa e n o
HTTP lood p o ec ion. US Pa en 7617170.
Pa en ed 2009.
[9] MIRKOVIC, J. and P. REIHER. A axonomy
o DDoS a ack and DDoS de ense. ACM SIG-
COMM Compu e Communica ion Re iew. 2004,
ol. 34, no. 2, pp. 39–53. ISSN 0146-4833.
DOI: 10.1145/997150.997156.
[10] PENG, T., C. LECKIE and K. RAMAMOHA-
NARAO. Su ey o ne wo k-based de ense mech-
anisms coun e ing he DoS and DDoS p ob-
lems. ACM Compu ing Su eys (CSUR). 2007,
ol. 39, no. 1, pp. 1–42. ISSN 0360-0300.
DOI: 10.1145/1216370.1216373.
[11] Global applica ion & ne wo k secu i y epo
2013. RADWARE. 2013.
[12] BAO, X. and H. HONG. NSFOCUS DDoS h ea
epo 2013. NSFOCUS In o ma ion Technology.
2013.
[13] P olexic qua e ly global DDoS A ack Repo
Q1-Q4. AKAMAI. 2013.
[14] Global applica ion & ne wo k secu i y epo
2014. RADWARE. 2014.
[15] HANSEN, R. Slowlo is HTTP DoS. Hack-
e s.o g [online]. 2014. A ailable a : h p://ha.
cke s.o g/slowlo is/.
[16] Dis ibu ed denial o se ice ends epo .
VERISIGN. 2014.
[17] PLXse ’s Q4 2014 s a e o he in e ne –Secu i y
Repo . AKAMAI. 2014.
[18] ZARGAR, S. T., J. JOSHI and D. TIPPER.
A Su ey o De ense Mechanisms Agains Dis-
ibu ed Denial o Se ice (DDoS) Flooding A -
acks. IEEE Communica ions Su eys &Tu o i-
als. 2004, ol. 15, no. 4, pp. 2046–2069. ISSN 1553-
877X. DOI: 10.1109/SURV.2013.031413.00127.
[19] JALILI, R., F. IMANI-MEHR, M. AMINI and
H. R. SHAHRIARI. De ec ion o Dis ibu ed De-
nial o Se ice A acks Using S a is ical P e-
p ocesso and Unsupe ised Neu al Ne wo ks. In-
o ma ion Secu i y P ac ice and Expe ience. 2005,
ol. 3439, iss. 1, pp. 192–203. ISSN 0302-9743.
DOI: 10.1007/978-3-540-31979-5_17.
[20] KANG, S. H., K. Y. PARK, S. G. YOO
and J. KIM. DDoS a oidance s a egy o
se ice a ailabili y. Clus e Compu ing. 2013,
ol. 16, no. 2, pp. 241–248. ISSN 1386-7857.
DOI: 10.1007/s10586-011-0185-4.
c
2015 ADVANCES IN ELECTRICAL AND ELECTRONIC ENGINEERING 329
INFORMATION AND COMMUNICATION TECHNOLOGIES AND SERVICES VOLUME: 13 |NUMBER: 4 |2015 |SPECIAL ISSUE
[21] WALFISH, M., M. VUTUKURU, H. BAL-
AKRISHNAN, D. KARGER and S. SHENKER.
DDoS de ense by o ense. In: P oceedings o
he 2006 con e ence on Applica ions, echnolo-
gies, a chi ec u es, and p o ocols o compu e
communica ions (SIGCOMM 2006). New Yo k:
ACM, 2006, pp. 303–314. ISBN 1-59593-308-5.
DOI: 10.1145/1159913.1159948.
[22] BELENKY, A. and N. ANSARI. On de e min-
is ic packe ma king. Compu e Ne wo ks. 2007,
ol. 51, no. 10, pp. 2677–2700. ISSN 1389-1286.
DOI: 10.1016/j.comne .2006.11.020.
[23] SEVAGE, S., D. WETHERALL, A. KARLIN and
T. ANDERSON. P ac ical ne wo k suppo o IP
aceback. ACM SIGCOMM Compu e Commu-
nica ion Re iew. 2000, ol. 30, no. 4, pp. 295–306.
ISSN 0146-4833. DOI: 10.1145/347057.347560.
[24] PATEL, C. M. and V. BORISAGAR. Su ey On
Taxonomy O Ddos A acks Wi h Impac And
Mi iga ion Techniques. In e na ional Jou nal o
Enginee ing Resea ch &Technology. 2012, ol. 1,
no. 9, pp. 1–8. ISSN 2278-0181.
[25] JAIN, A. and A. K. SINGH. Dis ibu ed denial o
se ice (DDoS) a acks-classi ica ion and implica-
ions. Jou nal o In o ma ion &Ope a ions Man-
agemen . 2012, ol. 3, no. 1, pp. 136. ISSN 0976-
7754.
[26] LOUKAS, G. and G. OEKE. P o ec ion agains
denial o se ice a acks: A su ey. The Com-
pu e Jou nal. 2010, ol. 53, no. 7, pp. 1020–1037.
ISSN 1020-1037.
Abou Au ho s
Zdenek MARTINASEK Recei ed M.Sc. (Ing.) a
he Depa men o Telecommunica ions a he Facul y
o Elec ical Enginee ing and Communica ion a B no
Uni e si y o Technology in 2008. He ecei ed Ph.D.
a he same Depa men . He also helps o co e
pedagogically Mas e ’s p og am cou se. The a ea
o his p o essional in e es s is c yp og aphy, powe
analysis, senso s and mode n da a communica ion.
c
2015 ADVANCES IN ELECTRICAL AND ELECTRONIC ENGINEERING 330