Traceback Model for Identifying Sources of Distributed Attacks in Real Time
Locating sources of distributed attack is time-consuming; attackers are identified long after the attack is completed. This paper proposes a trackback model for identifying attackers and locating their distributed sources in real time. Attackers are identified by monitoring violations of malicious e...
Main Authors: | , , |
---|---|
Format: | Article |
Language: | English |
Published: |
Wiley
2016
|
Subjects: | |
Online Access: | http://umpir.ump.edu.my/id/eprint/12717/1/Traceback%20Model%20for%20Identifying%20Sources%20of%20Distributed%20Attacks%20In%20Real%20Time.pdf |
_version_ | 1796991209022947328 |
---|---|
author | Ahmed, Abdulghani Ali Sadiq, Ali Safa Mohamad Fadli, Zolkipli |
author_facet | Ahmed, Abdulghani Ali Sadiq, Ali Safa Mohamad Fadli, Zolkipli |
author_sort | Ahmed, Abdulghani Ali |
collection | UMP |
description | Locating sources of distributed attack is time-consuming; attackers are identified long after the attack is completed. This paper proposes a trackback model for identifying attackers and locating their distributed sources in real time. Attackers are identified by monitoring violations of malicious end users on their bandwidth shares predefined in the service level agreement. Then, active connections of the malicious users are investigated to locate the host machines used as distributed sources of attack traffic. Mathematical model and simulation results demonstrate that the proposed model can reduce the required time for identifying malicious users and locating host machines used as the actual sources of attack packets |
first_indexed | 2024-03-06T12:02:44Z |
format | Article |
id | UMPir12717 |
institution | Universiti Malaysia Pahang |
language | English |
last_indexed | 2024-03-06T12:02:44Z |
publishDate | 2016 |
publisher | Wiley |
record_format | dspace |
spelling | UMPir127172018-03-30T08:14:28Z http://umpir.ump.edu.my/id/eprint/12717/ Traceback Model for Identifying Sources of Distributed Attacks in Real Time Ahmed, Abdulghani Ali Sadiq, Ali Safa Mohamad Fadli, Zolkipli QA Mathematics QA75 Electronic computers. Computer science Locating sources of distributed attack is time-consuming; attackers are identified long after the attack is completed. This paper proposes a trackback model for identifying attackers and locating their distributed sources in real time. Attackers are identified by monitoring violations of malicious end users on their bandwidth shares predefined in the service level agreement. Then, active connections of the malicious users are investigated to locate the host machines used as distributed sources of attack traffic. Mathematical model and simulation results demonstrate that the proposed model can reduce the required time for identifying malicious users and locating host machines used as the actual sources of attack packets Wiley 2016 Article PeerReviewed application/pdf en http://umpir.ump.edu.my/id/eprint/12717/1/Traceback%20Model%20for%20Identifying%20Sources%20of%20Distributed%20Attacks%20In%20Real%20Time.pdf Ahmed, Abdulghani Ali and Sadiq, Ali Safa and Mohamad Fadli, Zolkipli (2016) Traceback Model for Identifying Sources of Distributed Attacks in Real Time. Security and Communication Networks, 9 (13). pp. 2173-2185. ISSN 1939-0122. (Published) http://dx.doi.org/10.1002/sec.1476 DOI: 10.1002/sec.1476 |
spellingShingle | QA Mathematics QA75 Electronic computers. Computer science Ahmed, Abdulghani Ali Sadiq, Ali Safa Mohamad Fadli, Zolkipli Traceback Model for Identifying Sources of Distributed Attacks in Real Time |
title | Traceback Model for Identifying Sources of Distributed
Attacks in Real Time |
title_full | Traceback Model for Identifying Sources of Distributed
Attacks in Real Time |
title_fullStr | Traceback Model for Identifying Sources of Distributed
Attacks in Real Time |
title_full_unstemmed | Traceback Model for Identifying Sources of Distributed
Attacks in Real Time |
title_short | Traceback Model for Identifying Sources of Distributed
Attacks in Real Time |
title_sort | traceback model for identifying sources of distributed attacks in real time |
topic | QA Mathematics QA75 Electronic computers. Computer science |
url | http://umpir.ump.edu.my/id/eprint/12717/1/Traceback%20Model%20for%20Identifying%20Sources%20of%20Distributed%20Attacks%20In%20Real%20Time.pdf |
work_keys_str_mv | AT ahmedabdulghaniali tracebackmodelforidentifyingsourcesofdistributedattacksinrealtime AT sadiqalisafa tracebackmodelforidentifyingsourcesofdistributedattacksinrealtime AT mohamadfadlizolkipli tracebackmodelforidentifyingsourcesofdistributedattacksinrealtime |