A rerouting system for mitigating target host disconnections on active sinkhole-based defense mechanism (ConnectiRoute)

There is a large pool of solutions to keep a network secure, however, all networks are still prone to Denial of Service (DoS) or Distributed DoS (DDoS) attacks which flood the network and may lead to degradation of the connection. Providing protection against these kinds of attacks is challenging be...

Full description

Saved in:
Bibliographic Details
Main Authors: Legaspi, Renz Jerome V., Patricio, Angelo T., Tan, Carl Anthony O.
Format: text
Language:English
Published: Animo Repository 2014
Subjects:
Online Access:https://animorepository.dlsu.edu.ph/etd_bachelors/10623
Tags: Add Tag
No Tags, Be the first to tag this record!
Institution: De La Salle University
Language: English
Description
Summary:There is a large pool of solutions to keep a network secure, however, all networks are still prone to Denial of Service (DoS) or Distributed DoS (DDoS) attacks which flood the network and may lead to degradation of the connection. Providing protection against these kinds of attacks is challenging because every attack has a different behavior from the other. To be able to protect networks against such attack, a solution composed of the combination of network attack redirection, isolation and analysis was proposed which is popularly called as Sinkholes which is a kind of network defense where intrusions are redirected or rerouted to an assigned defense node in a network and isolates it. While being isolated, the attack is analysed to obtain the type of intrusion, its behavior, the target area and presumably study the trends of intrusions in different targets and situations. The problem, however, is that the network, while protected under such type of network defense, can experience internet disconnection because once it is activated, it will redirect all the traffic to the sinkhole. The goal of this study is to create a system that will isolate DoS/DDoS attacks while maintaining connectivity of the legitimate network traffic.