R. Zebari, Subhi R. M. Zeebaree, A. Sallow, Hanan M. Shukur, Omar M. Ahmad, Karwan Jacksi
{"title":"使用高可用性代理和网络负载平衡缓解分布式拒绝服务攻击","authors":"R. Zebari, Subhi R. M. Zeebaree, A. Sallow, Hanan M. Shukur, Omar M. Ahmad, Karwan Jacksi","doi":"10.1109/ICOASE51841.2020.9436545","DOIUrl":null,"url":null,"abstract":"Nowadays, cybersecurity threat is a big challenge to all organizations that present their services over the Internet. Distributed Denial of Service (DDoS) attack is the most effective and used attack and seriously affects the quality of service of each E-organization. Hence, mitigation this type of attack is considered a persistent need. In this paper, we used Network Load Balancing (NLB) and High Availability Proxy (HAProxy) as mitigation techniques. The NLB is used in the Windows platform and HAProxy in the Linux platform. Moreover, Internet Information Service (IIS) 10.0 is implemented on Windows server 2016 and Apache 2 on Linux Ubuntu 16.04 as web servers. We evaluated each load balancer efficiency in mitigating synchronize (SYN) DDoS attack on each platform separately. The evaluation process is accomplished in a real network and average response time and average CPU are utilized as metrics. The results illustrated that the NLB in the Windows platform achieved better performance in mitigation SYN DDOS compared to HAProxy in the Linux platform. Whereas, the average response time of the Window webservers is reduced with NLB. However, the impact of the SYN DDoS on the average CPU usage of the IIS 10.0 webservers was more than those of the Apache 2 webservers.","PeriodicalId":126112,"journal":{"name":"2020 International Conference on Advanced Science and Engineering (ICOASE)","volume":"54 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-12-23","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"14","resultStr":"{\"title\":\"Distributed Denial of Service Attack Mitigation using High Availability Proxy and Network Load Balancing\",\"authors\":\"R. Zebari, Subhi R. M. Zeebaree, A. Sallow, Hanan M. Shukur, Omar M. Ahmad, Karwan Jacksi\",\"doi\":\"10.1109/ICOASE51841.2020.9436545\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Nowadays, cybersecurity threat is a big challenge to all organizations that present their services over the Internet. Distributed Denial of Service (DDoS) attack is the most effective and used attack and seriously affects the quality of service of each E-organization. Hence, mitigation this type of attack is considered a persistent need. In this paper, we used Network Load Balancing (NLB) and High Availability Proxy (HAProxy) as mitigation techniques. The NLB is used in the Windows platform and HAProxy in the Linux platform. Moreover, Internet Information Service (IIS) 10.0 is implemented on Windows server 2016 and Apache 2 on Linux Ubuntu 16.04 as web servers. We evaluated each load balancer efficiency in mitigating synchronize (SYN) DDoS attack on each platform separately. The evaluation process is accomplished in a real network and average response time and average CPU are utilized as metrics. The results illustrated that the NLB in the Windows platform achieved better performance in mitigation SYN DDOS compared to HAProxy in the Linux platform. Whereas, the average response time of the Window webservers is reduced with NLB. However, the impact of the SYN DDoS on the average CPU usage of the IIS 10.0 webservers was more than those of the Apache 2 webservers.\",\"PeriodicalId\":126112,\"journal\":{\"name\":\"2020 International Conference on Advanced Science and Engineering (ICOASE)\",\"volume\":\"54 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2020-12-23\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"14\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2020 International Conference on Advanced Science and Engineering (ICOASE)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ICOASE51841.2020.9436545\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2020 International Conference on Advanced Science and Engineering (ICOASE)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICOASE51841.2020.9436545","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 14
摘要
如今,网络安全威胁对所有通过互联网提供服务的组织来说都是一个巨大的挑战。分布式拒绝服务攻击(Distributed Denial of Service, DDoS)是一种最有效、最常用的攻击方式,严重影响着各个电子机构的服务质量。因此,缓解这种类型的攻击被认为是一种持久的需求。在本文中,我们使用网络负载平衡(NLB)和高可用性代理(HAProxy)作为缓解技术。NLB应用于Windows平台,HAProxy应用于Linux平台。Internet Information Service (IIS) 10.0是在Windows server 2016上实现的,Apache 2是在Linux Ubuntu 16.04上实现的。我们在每个平台上分别评估了每个负载均衡器在缓解同步(SYN) DDoS攻击方面的效率。评估过程在真实网络中完成,并使用平均响应时间和平均CPU作为指标。结果表明,与Linux平台的HAProxy相比,Windows平台的NLB在缓解SYN DDOS攻击方面具有更好的性能。然而,使用NLB可以减少windows web服务器的平均响应时间。但是,SYN DDoS攻击对IIS 10.0服务器平均CPU占用率的影响要大于Apache 2服务器。
Distributed Denial of Service Attack Mitigation using High Availability Proxy and Network Load Balancing
Nowadays, cybersecurity threat is a big challenge to all organizations that present their services over the Internet. Distributed Denial of Service (DDoS) attack is the most effective and used attack and seriously affects the quality of service of each E-organization. Hence, mitigation this type of attack is considered a persistent need. In this paper, we used Network Load Balancing (NLB) and High Availability Proxy (HAProxy) as mitigation techniques. The NLB is used in the Windows platform and HAProxy in the Linux platform. Moreover, Internet Information Service (IIS) 10.0 is implemented on Windows server 2016 and Apache 2 on Linux Ubuntu 16.04 as web servers. We evaluated each load balancer efficiency in mitigating synchronize (SYN) DDoS attack on each platform separately. The evaluation process is accomplished in a real network and average response time and average CPU are utilized as metrics. The results illustrated that the NLB in the Windows platform achieved better performance in mitigation SYN DDOS compared to HAProxy in the Linux platform. Whereas, the average response time of the Window webservers is reduced with NLB. However, the impact of the SYN DDoS on the average CPU usage of the IIS 10.0 webservers was more than those of the Apache 2 webservers.