Please use this identifier to cite or link to this item: https://dspace.iiti.ac.in/handle/123456789/4976
Full metadata record
DC FieldValueLanguage
dc.contributor.authorHubballi, Neminathen_US
dc.date.accessioned2022-03-17T01:00:00Z-
dc.date.accessioned2022-03-17T15:36:18Z-
dc.date.available2022-03-17T01:00:00Z-
dc.date.available2022-03-17T15:36:18Z-
dc.date.issued2017-
dc.identifier.citationHubballi, N., & Tripathi, N. (2017). An event based technique for detecting spoofed IP packets. Journal of Information Security and Applications, 35, 32-43. doi:10.1016/j.jisa.2017.04.001en_US
dc.identifier.issn2214-2134-
dc.identifier.otherEID(2-s2.0-85019244469)-
dc.identifier.urihttps://doi.org/10.1016/j.jisa.2017.04.001-
dc.identifier.urihttps://dspace.iiti.ac.in/handle/123456789/4976-
dc.description.abstractDistributed Denial of Service (DDoS) attacks are one of the prominent network security attacks. In DDoS attack several machines send large amount of network traffic to the victim using spoofed IP address. Unfortunately there is no reliable technique to detect spoofed IP packets. In this paper we argue that, a proactive detection of spoofed IP packets will help in predicting DDoS attacks. In this paper we describe an event based detection method to identify spoofed IP packets. Our method works by proactively probing received packets for genuineness. Active probing technique uses inconsistencies in TTL values of received packets to decide whether the first packet was spoofed or genuine. We enumerate several possible spoofing scenarios with our detection method in place and identify its type based on the response to probing. Further, we study limitations of event based method and discuss ways to overcome those. We design and experiment with all spoofing scenarios in a real network setup and report the results. With few optimizations done to the probing strategy, the overhead incurred can be minimized considerably, which makes the proposed technique useful for detecting DDoS attacks. © 2017en_US
dc.language.isoenen_US
dc.publisherElsevier Ltden_US
dc.sourceJournal of Information Security and Applicationsen_US
dc.subjectDiscrete event simulationen_US
dc.subjectInternet protocolsen_US
dc.subjectNetwork securityen_US
dc.subjectActive probing techniquesen_US
dc.subjectDetection methodsen_US
dc.subjectDistributed denial of service attacken_US
dc.subjectEvent-baseden_US
dc.subjectEvent-based methoden_US
dc.subjectIP addresssen_US
dc.subjectNetwork trafficen_US
dc.subjectProbing strategiesen_US
dc.subjectDenial-of-service attacken_US
dc.titleAn event based technique for detecting spoofed IP packetsen_US
dc.typeJournal Articleen_US
Appears in Collections:Department of Computer Science and Engineering

Files in This Item:
There are no files associated with this item.


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.

Altmetric Badge: