A Defence Mechanism: DNS based DDoS Attack

Authors : Arpita Narayan, Upendra Kumar


Arpita Narayan, Upendra Kumar "A Defence Mechanism: DNS based DDoS Attack". International Journal of Computer Trends and Technology (IJCTT) V33(1):1-8, March 2016.

Distributed Denial of Service (DDoS) attacks pose one of the most serious security threats to the Internet. In this work, we aimed to develop a collaborative defence framework against DNS based DDoS reflection and amplification attacks in networks. We focus on two main phases, which are victim detection and filtering of malicious traffic, to achieve a successful defence against DNS reflection attack and prevention against amplification attack. We propose an efficient server level approach to identify victim IP accurately and responsively by using unusual request count. Once the victim IP is confirmed, our approach is then to use HOP count i.e. number of router packets passes to reach destination, to filter out the entire illegitimate request.

Distributed Denial of Service attacks (DDoS), Domain Name System (DNS), DNS message sequence, HOP count, Reflection attack, Amplification attack.