Please use this identifier to cite or link to this item:
https://dspace.iiti.ac.in/handle/123456789/4931
Full metadata record
DC Field | Value | Language |
---|---|---|
dc.contributor.author | Hubballi, Neminath | en_US |
dc.date.accessioned | 2022-03-17T01:00:00Z | - |
dc.date.accessioned | 2022-03-17T15:36:06Z | - |
dc.date.available | 2022-03-17T01:00:00Z | - |
dc.date.available | 2022-03-17T15:36:06Z | - |
dc.date.issued | 2018 | - |
dc.identifier.citation | Hubballi, N., & Santini, J. (2018). Detecting TCP ACK storm attack: A state transition modelling approach. IET Networks, 7(6), 429-434. doi:10.1049/iet-net.2018.5003 | en_US |
dc.identifier.issn | 2047-4954 | - |
dc.identifier.other | EID(2-s2.0-85055950840) | - |
dc.identifier.uri | https://doi.org/10.1049/iet-net.2018.5003 | - |
dc.identifier.uri | https://dspace.iiti.ac.in/handle/123456789/4931 | - |
dc.description.abstract | Ack-storm DoS attacks are injection attacks against an active Transmission Control Protocol (TCP) connection. These attacks can be generated by a very weak adversary and can generate amplification factor of orders of magnitude by exploiting a weakness in the TCP protocol specification. This attack requires sending two packets by the adversary with acknowledgement number greater than the sequence number used in each direction and the two end hosts will attempt to resynchronise the sequence numbers by sending duplicate acknowledgement and enter a loop. In this study, the authors propose a state transition model based detection scheme to detect these DoS attacks. This state transition machine called constrained counting automata (CCA) has the ability to count the number of times a state has been revisited and its transitions are constrained by invariant conditions to be satisfied. They model the chances of receiving a packet with acknowledgement number greater than the sequence number used by its peer as a probability distribution and use it to set appropriate value of threshold on revisits of a state for detecting attack. By experimenting within a local network and in Internet, they show that CCA can detect Ack-storm DoS attacks. © The Institution of Engineering and Technology 2018. | en_US |
dc.language.iso | en | en_US |
dc.publisher | Institution of Engineering and Technology | en_US |
dc.source | IET Networks | en_US |
dc.subject | Denial-of-service attack | en_US |
dc.subject | Probability distributions | en_US |
dc.subject | Storms | en_US |
dc.subject | Amplification factors | en_US |
dc.subject | Detecting attacks | en_US |
dc.subject | Detection scheme | en_US |
dc.subject | Invariant condition | en_US |
dc.subject | Orders of magnitude | en_US |
dc.subject | Sequence number | en_US |
dc.subject | State transition models | en_US |
dc.subject | State transitions | en_US |
dc.subject | Transmission control protocol | en_US |
dc.title | Detecting TCP ACK storm attack: A state transition modelling approach | en_US |
dc.type | Journal Article | en_US |
Appears in Collections: | Department of Computer Science and Engineering |
Files in This Item:
There are no files associated with this item.
Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.
Altmetric Badge: