Kabir, Kantola, and Llorente Santos
220
inbound connection. Figure 9.10 presents this delay in assigning a TCP‐half connection
state due to use of TCP‐Splice. In a real network, the end‐to‐end latency for TCP
messages would be added to compute the total delay in assigning the half‐state. It is
possible to reduce the average delay penalty caused by the TCP Splice by using it
selectively, that is, on privileged ports, or under network attacks only.
To test the effectiveness of the Bot‐detection method, we subjected RGW to malicious
flows (i.e. network scans) from the non‐spoofed sources, emulating a botnet. Figure 9.11
10
20
30
Time delay in assigning the half-connection state (in msec)
40
Probability distribution
50
60
70
80
RGW without TCP-Splice
RGW with TCP-Splice
90
0.055
0.05
0.045
0.04
0.035
0.03
0.025
0.02
0.015
0.01
0.005
Figure 9.10 Delay in assigning TCP half‐connection state due to TCP‐Splice.
40
35
30
25
20
15
10
SYN flood rate towards RGW
5
0 0
1
2
3
4
5
Time scale (in seconds)
Offered load: 60 connections/sec
Offered load: 50 connections/sec
Offered load: 40 connections/sec
DDoS Mitigation via Bot-detection method
6
7
8
9
10
11
Figure 9.11 Bot‐Detection method to mitigate SYN flood from botnets (non‐spoofed sources).
Précédent

- 262/483

Suivant