Walter Fuertes, Miguel Morales, Hernán Aules, T. Toulkeridis
{"title":"Software-based computing platform as an experimental topology assembled to detect and mitigate DDoS attacks using virtual environments","authors":"Walter Fuertes, Miguel Morales, Hernán Aules, T. Toulkeridis","doi":"10.1109/SPECTS.2016.7570512","DOIUrl":null,"url":null,"abstract":"A software-based computing platform has been constructed as an experimental topology with the goal to detect and mitigate DDoS using a Virtual Network Environment. This research comprises the automatic management of three main approaches, being firstly the deployment of a virtual infrastructure for experimentation, secondly the configuration of the detection and mitigation of DDoS attacks and finally the analytical tools to corroborate with introduced countermeasures. In order to accomplish these purposes, we have designed and constructed an experimental topology based on virtual networks, which injects and mitigates DDoS attacks. Simultaneously, we designed and developed a software application to manage automatically the deployment of the experimental topology and the configuration of the detection and mitigation of DDoS attacks. To guarantee the reliability of the outcome, we configured a rule-based detection mechanism for Linux through the optimization of an algorithm that resolves anomalies in firewalls rules. The results demonstrate quantitatively the efficiency of this proposal.","PeriodicalId":302558,"journal":{"name":"2016 International Symposium on Performance Evaluation of Computer and Telecommunication Systems (SPECTS)","volume":"1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2016-07-24","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2016 International Symposium on Performance Evaluation of Computer and Telecommunication Systems (SPECTS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SPECTS.2016.7570512","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3
Abstract
A software-based computing platform has been constructed as an experimental topology with the goal to detect and mitigate DDoS using a Virtual Network Environment. This research comprises the automatic management of three main approaches, being firstly the deployment of a virtual infrastructure for experimentation, secondly the configuration of the detection and mitigation of DDoS attacks and finally the analytical tools to corroborate with introduced countermeasures. In order to accomplish these purposes, we have designed and constructed an experimental topology based on virtual networks, which injects and mitigates DDoS attacks. Simultaneously, we designed and developed a software application to manage automatically the deployment of the experimental topology and the configuration of the detection and mitigation of DDoS attacks. To guarantee the reliability of the outcome, we configured a rule-based detection mechanism for Linux through the optimization of an algorithm that resolves anomalies in firewalls rules. The results demonstrate quantitatively the efficiency of this proposal.