Distributed Denial of Service Attack Mitigation using High Availability Proxy and Network Load Balancing

R. Zebari, Subhi R. M. Zeebaree, A. Sallow, Hanan M. Shukur, Omar M. Ahmad, Karwan Jacksi
{"title":"Distributed Denial of Service Attack Mitigation using High Availability Proxy and Network Load Balancing","authors":"R. Zebari, Subhi R. M. Zeebaree, A. Sallow, Hanan M. Shukur, Omar M. Ahmad, Karwan Jacksi","doi":"10.1109/ICOASE51841.2020.9436545","DOIUrl":null,"url":null,"abstract":"Nowadays, cybersecurity threat is a big challenge to all organizations that present their services over the Internet. Distributed Denial of Service (DDoS) attack is the most effective and used attack and seriously affects the quality of service of each E-organization. Hence, mitigation this type of attack is considered a persistent need. In this paper, we used Network Load Balancing (NLB) and High Availability Proxy (HAProxy) as mitigation techniques. The NLB is used in the Windows platform and HAProxy in the Linux platform. Moreover, Internet Information Service (IIS) 10.0 is implemented on Windows server 2016 and Apache 2 on Linux Ubuntu 16.04 as web servers. We evaluated each load balancer efficiency in mitigating synchronize (SYN) DDoS attack on each platform separately. The evaluation process is accomplished in a real network and average response time and average CPU are utilized as metrics. The results illustrated that the NLB in the Windows platform achieved better performance in mitigation SYN DDOS compared to HAProxy in the Linux platform. Whereas, the average response time of the Window webservers is reduced with NLB. However, the impact of the SYN DDoS on the average CPU usage of the IIS 10.0 webservers was more than those of the Apache 2 webservers.","PeriodicalId":126112,"journal":{"name":"2020 International Conference on Advanced Science and Engineering (ICOASE)","volume":"54 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-12-23","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"14","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2020 International Conference on Advanced Science and Engineering (ICOASE)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICOASE51841.2020.9436545","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 14

Abstract

Nowadays, cybersecurity threat is a big challenge to all organizations that present their services over the Internet. Distributed Denial of Service (DDoS) attack is the most effective and used attack and seriously affects the quality of service of each E-organization. Hence, mitigation this type of attack is considered a persistent need. In this paper, we used Network Load Balancing (NLB) and High Availability Proxy (HAProxy) as mitigation techniques. The NLB is used in the Windows platform and HAProxy in the Linux platform. Moreover, Internet Information Service (IIS) 10.0 is implemented on Windows server 2016 and Apache 2 on Linux Ubuntu 16.04 as web servers. We evaluated each load balancer efficiency in mitigating synchronize (SYN) DDoS attack on each platform separately. The evaluation process is accomplished in a real network and average response time and average CPU are utilized as metrics. The results illustrated that the NLB in the Windows platform achieved better performance in mitigation SYN DDOS compared to HAProxy in the Linux platform. Whereas, the average response time of the Window webservers is reduced with NLB. However, the impact of the SYN DDoS on the average CPU usage of the IIS 10.0 webservers was more than those of the Apache 2 webservers.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
使用高可用性代理和网络负载平衡缓解分布式拒绝服务攻击
如今,网络安全威胁对所有通过互联网提供服务的组织来说都是一个巨大的挑战。分布式拒绝服务攻击(Distributed Denial of Service, DDoS)是一种最有效、最常用的攻击方式,严重影响着各个电子机构的服务质量。因此,缓解这种类型的攻击被认为是一种持久的需求。在本文中,我们使用网络负载平衡(NLB)和高可用性代理(HAProxy)作为缓解技术。NLB应用于Windows平台,HAProxy应用于Linux平台。Internet Information Service (IIS) 10.0是在Windows server 2016上实现的,Apache 2是在Linux Ubuntu 16.04上实现的。我们在每个平台上分别评估了每个负载均衡器在缓解同步(SYN) DDoS攻击方面的效率。评估过程在真实网络中完成,并使用平均响应时间和平均CPU作为指标。结果表明,与Linux平台的HAProxy相比,Windows平台的NLB在缓解SYN DDOS攻击方面具有更好的性能。然而,使用NLB可以减少windows web服务器的平均响应时间。但是,SYN DDoS攻击对IIS 10.0服务器平均CPU占用率的影响要大于Apache 2服务器。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
COVID-19 Diagnosis Systems Based on Deep Convolutional Neural Networks Techniques: A Review Fake News Detection Using Machine Learning and Deep Learning Algorithms Transcript Validation System using biometric characteristics COVID-19 Diagnosis from Chest X-ray Images Using Deep Learning Approach Hate Speech Detection Using Genetic Programming
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1