Presentation is loading. Please wait.

Presentation is loading. Please wait.

Study on network safety strategy against DDoS attack 102064515 林昀欣 2010 IEEE International Conference on Advanced Management Science (ICAMS) Xiaoming Bi,

Similar presentations


Presentation on theme: "Study on network safety strategy against DDoS attack 102064515 林昀欣 2010 IEEE International Conference on Advanced Management Science (ICAMS) Xiaoming Bi,"— Presentation transcript:

1 Study on network safety strategy against DDoS attack 102064515 林昀欣 2010 IEEE International Conference on Advanced Management Science (ICAMS) Xiaoming Bi, Qiansheng Zheng(Correspondence Author)

2 Outline  DDoS Attacks Principle  SOA (Service-Oriented Architecture)  SOAP (Simple Object Access Protocol)  SOA-based DDoS Defense Framework  Verification  Conclusion  Reference 2/11

3 DDoS Attacks Principle  use reasonable service request  manufacture large useless data  use connection defects of provided service  send malformed data 3/11

4 DDoS Attacks Principle (cont.)  Smurf attack  Fraggle attack  Trinoo attack  TFN2k attack 4/11

5 SOA (Service-Oriented Architecture)  a component model  three elements: services, loosely coupled, message delivery  example: Web Service 5/11

6 SOAP (Simple Object Access Protocol)  use XML (Extensible Markup Language)  contain sub-elements Header and Body within the Envelope  exchange structured information 6/11

7 SOA-based DDoS Defense Framework  overlay network: routing node, serving node  communications between nodes are encrypted  hide the location of the server  clients have to request for certificate first  allocate different bandwidth to different flows 0.1 for request flow, 0.9 for flow with certificate  use client puzzle mechanism  internal restructuring 7/11

8 SOA-based DDoS Defense Framework (cont.)  four packet types: request, response, normal, update  final certificate is composed of pre-certificate, byte limit and time limit 8/11

9 Verification  upstream bandwidth of clients and attackers = 1MB/s bandwidth between routing and service nodes = 10MB/s  Test 1: client sends document around 100MB attacker sends large number of requests  Test 2: client sends document around 100MB attacker sends large number of data packets (internal collaborators exist) 9/11 attack is launched129 seconds attack is not launched127 seconds attack is launched243 seconds attack is not launched127 seconds

10 Conclusion  this framework is effective 10/11

11 Reference  What Is Service-Oriented Architecture http://www.xml.com/pub/a/ws/2003/09/30/soa.html  What Is SOA http://serviceorientation.com/whatissoa/index  SOAP Version 1.2 http://www.w3.org/TR/soap12-part1/ 11/11


Download ppt "Study on network safety strategy against DDoS attack 102064515 林昀欣 2010 IEEE International Conference on Advanced Management Science (ICAMS) Xiaoming Bi,"

Similar presentations


Ads by Google