UUM Electronic Theses and Dissertation
UUM ETD | Universiti Utara Malaysian Electronic Theses and Dissertation
FAQs | Feedback | Search Tips | Sitemap

Distributed denial of service detection using stepping stone detection method in internet control message protocol attack

Nor Izham, Subri (2017) Distributed denial of service detection using stepping stone detection method in internet control message protocol attack. Masters thesis, Universiti Utara Malaysia.

[thumbnail of s816991_01.pdf] Text
s816991_01.pdf

Download (2MB)
[thumbnail of s816991_02.pdf] Text
s816991_02.pdf

Download (1MB)
[thumbnail of s816991_references.docx] Text
s816991_references.docx

Download (70kB)

Abstract

The Distributed Denial of Services (DDoS) is an imminent attack that can threaten cyber security even tough the attack is simple. The goal of DDoS attack is to disrupt the services that being provided by a server by forcing the server to a halt. This attack actually is an attack that being conducted by overwhelming the victim using large amount of host that sends request that need to be processed by the server. DDoS attack using ICMP as a medium prove to be a challenge to cyber security prevention system and application. This is because ICMP-based DDoS attack has a
characteristic such as not containing malicious content. Therefore, ICMP-based DDoS attack is hard to be detected by cyber security prevention system and application. The goal of this research is to detect DDoS attack using Stepping Stone Detection (SSD) method. The objective of this research is to develop different approach to detect DDoS attack. There are six stages involved in this research which are analysis, instrument, design, experiment, data collection, and evaluation. The experiment is using testbed where actual hardware is used in a controlled environment where the data obtained is not polluted with other elements. Lastly, False Positive Rate (FPR) is compared so the efficiency of SSD-based method to detect DDoS can be identified. This research shows that SSD-based method obtained low FPR which is 0.206% rather than Snort that obtain 63.04%. This shows that SSD-based method is more efficient to detect ICMP-based DDoS attack than Snort in terms of FPR. As a conclusion, this research shows that SSD capable to detect ICMP-based DDoS attack and achieve the objectives of this research.

Item Type: Thesis (Masters)
Supervisor : Omar, Mohd Nizam and Din, Roshidi
Item ID: 9098
Uncontrolled Keywords: Distributed Denial of Services, Stepping Stone Detection, DDoS attack detection, Internet Control Message Protocol attack, ICMP-based DDoS attack.
Subjects: T Technology > T Technology (General) > T58.5-58.64 Information technology
Divisions: Awang Had Salleh Graduate School of Arts & Sciences
Date Deposited: 06 Mar 2022 03:43
Last Modified: 06 Mar 2022 03:43
Department: Awang Had Salleh Graduate School of Arts & Sciences
Name: Omar, Mohd Nizam and Din, Roshidi
URI: https://etd.uum.edu.my/id/eprint/9098

Actions (login required)

View Item
View Item