Skip to main navigation Skip to search Skip to main content

D-RNA: Towards a DDoS resistant network architecture using social network analysis

  • SUNY Buffalo

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Distributed Denial of Service (DDoS) attack is a constant threat to the availability of network based services. Although a DDoS attack often has a distinctive pattern, a rigorous structural analysis of it as a preventive measure to address such attack is limited in the literature. In particular, the fact that a node's structural position in the physical network topology might add to its DDoS susceptibility is not well explored. In this paper, we use Social Network Analysis (SNA) based metrics to analyze the structure of a DDoS attack. For each node in the DDoS attack scenario, we measure three SNA based metrics: "Betweenness", "Hub and Authority" and "Maximum Similarity-based Hierarchical Clustering". Using these metrics, we develop an algorithm to structurally analyze any given network topology for DDoS susceptibility as well as node exploitability to a DDoS attack. Our simulation of DDoS attacks on NSFNET backbone network topology validates the practicality and effectiveness of the proposed analysis. This model can be used to re-examine existing network architectures and take necessary steps such as re-positioning a DDoS susceptible service-critical node to make the network more DDoS resistant.

Original languageEnglish
Title of host publication22nd International Conference on Computer Applications in Industry and Engineering 2009, CAINE 2009
Pages69-74
Number of pages6
StatePublished - 2009
Event22nd International Conference on Computer Applications in Industry and Engineering 2009, CAINE 2009 - San Francisco, CA, United States
Duration: Nov 4 2009Nov 6 2009

Publication series

Name22nd International Conference on Computer Applications in Industry and Engineering 2009, CAINE 2009

Conference

Conference22nd International Conference on Computer Applications in Industry and Engineering 2009, CAINE 2009
Country/TerritoryUnited States
CitySan Francisco, CA
Period11/4/0911/6/09

Keywords

  • Distributed Denial of Service (DDoS) Attack
  • Network topology
  • NSFNET
  • Social Network Analysis (SNA)

Fingerprint

Dive into the research topics of 'D-RNA: Towards a DDoS resistant network architecture using social network analysis'. Together they form a unique fingerprint.

Cite this