scholarly journals Efficient Authentication Mechanism for Defending Against Reflection-Based Attacks on Domain Name System

2020 ◽  
Vol 5 (1) ◽  
pp. 164-174
Author(s):  
Dana Hasan ◽  
Rebeen R. Hama Amin ◽  
Masnida Hussin

Domain Name System (DNS) is one of few services on the Internet which is allowed through every security barrier. It mostly depends on the User Datagram Protocol (UDP) as the transport protocol, which is a connectionless protocol with no built-in authentication mechanism. On top of that, DNS responses are substantially larger than their corresponding requests. These two key features made DNS a fabulous attacking tool for cybercriminals to reflect and amplify a huge volume of requests to consume their victim's resources. Recent incidents revealed how harsh DNS could be when it is abused with great complexity by attackers. Moreover, these events had proven that any defense mechanism with single point deployment couldn’t accurately and efficiently overcome an attack volume with high dynamicity. In this paper, we proposed the Efficient Distributed-based Defense Scheme (EDDS) to overcome the shortcomings of a centralized-based defense mechanism. By using an authentication message exchange, which is a Challenge-Handshake Authentication Protocol (CHAP)-based authentication mechanism. It is deployed on multiple nodes to determine the legitimacy of the DNS request. Moreover, it significantly reduces the impact of the amplification factor for the fake DNS requests without having any side effects on legitimate ones. Then, a Stateful Packet Inspection (SPI)-based packet filtering is proposed to distinguish legitimate requests from fake ones by considering the results of the authentication procedure. Both authentication-message exchange and SPI-based filtering are introduced to provide detection accuracy without reducing the quality of service for legitimate users. As the simulation results show, the proposed mechanism can efficiently and accurately detect, isolate, and discard the bogus traffic with minimal overhead on the system.

2021 ◽  
Vol 4 (1) ◽  
pp. 81-94
Author(s):  
Fahad Alatawi

Distributed Denial of Service (DDoS) remains a big concern in Cybersecurity. DDoS attacks are implemented to prevent legitimate users from getting access to services. The attackers make use of multiple hosts that have been compromised (i.e., Botnets) to organize a large-scale attack on targets. Developing an effective defensive mechanism against existing and potential DDoS attacks remains a strong desire in the cybersecurity research community. However, development of effective mechanisms or solutions require adequate evaluation of existing defense mechanism and a critical analysis of how these methods have been implemented in preventing, detecting, and responding to DDoS attacks. This paper adopted a systematic review method to critically analyze the existing mechanisms. The review of existing literature helped classify the defense mechanism into four categories: source-based, core-router, victim-based, and distributed systems. A qualitative analysis was used to exhaustively evaluate these defense mechanisms and determine their respective effectiveness. The effectiveness of the defense mechanisms was evaluated on six key parameters: coverage, implementation, deployment, detection accuracy, response mechanism, and robustness. The comparative analysis reviewed the shortcomings and benefits of each mechanism. The evaluation determined that victim-based defense mechanisms have a high detection accuracy but is associated with massive collateral as the detection happens when it is too late to protect the system. On the other hand, whereas stopping an attack from the source-end is ideal, detection accuracy at this point is too low as it is hard to differentiate legitimate and malicious traffic. The effectiveness of the core-based defense systems is not ideal because the routers do not have enough CPU cycles and memory to profile the traffic. Distributed defense mechanisms are effective as components can be spread out across the three locations in a way that takes advantage of each location. The paper also established that the rate-limiting response mechanism is more effective than packet filtering method because it does not restrict legitimate traffic. The analysis revealed that there is no single defense mechanism that offers complete protection against DDoS attacks but concludes that the best defense mechanism is the use of distributed defense because it ensures that defense components are placed on all locations.


Author(s):  
Rebeen Rebwar Hama Amin ◽  
Dana Hassan ◽  
Masnida Hussin

DNS reflection/amplification attacks are types of Distributed Denial of Service (DDoS) attacks that take advantage of vulnerabilities in the Domain Name System (DNS) and use it as an attacking tool. This type of attack can quickly deplete the resources (i.e. computational and bandwidth) of the targeted system. Many defense mechanisms are proposed to mitigate the impact of this type of attack. However, these defense mechanisms are centralized-based and cannot deal with a distributed-based attack. Also, these defense mechanisms have a single point of deployment which leads to a lack of computational resources to handle an attack with a large magnitude. In this work, we presented a new distributed-based defense mechanism (DDM) to counter reflection/ amplification attacks. While operating, we calculated the CPU counters of the machines that we deployed our defense mechanism with which showed 19.9% computational improvement. On top of that, our defense mechanism showed that it can protect the attack path from exhaustion during reflection/amplification attacks without putting any significant traffic load on the network by eliminating every spoofed request from getting responses.


2021 ◽  
Vol 80 (Suppl 1) ◽  
pp. 168.2-168
Author(s):  
L. Wagner ◽  
S. Sestini ◽  
C. Brown ◽  
A. Finglas ◽  
R. Francisco ◽  
...  

Background:Inborn metabolic disorders (IMDs) currently encompass more than 1,500 diseases with new ones still to be identified1. Each of them is characterised by a genetic defect affecting a metabolic pathway. Only few of them have curative treatments, that target the respective metabolic pathway. Commonly, treatment examples include diet, substrate reduction therapies, enzyme replacement therapies, gene therapy and biologicals, enabling IMD-patient now to survive to adulthood. About 30 % of all IMDs involve the musculoskeletal system and are here referred to as rare metabolic RMDs. Generally, IMDs are very heterogenous with respect to symptoms and severity, often being systemic and affecting more children than adults. Thus, challenges include certified advanced training of adult metabolic experts, standardised transition plans, social support and development of therapies for diseases that do not have any cure yet.Objectives:Introduction of MetabERN, its structure and objectives, highlighting on the unique features and challenges of metabolic RMDs and describing the involvement of patient representation in MetabERN.Methods:MetabERN is stratified in 7 subnetworks (SNW) according to the respective metabolic pathways and 9 work packages (WP), including administration, dissemination, guidelines, virtual counselling framework, research/clinical trials, continuity of care, education and patient involvement. The patient board involves a steering committee and single point of contacts for each subnetwork and work package, respectively2. Projects include identifying the need of implementing social science to assess the psycho-socio-economic burden of IMDs, webinars on IMDs and their transition as well as surveys on the impact of COVID-193 on IMD-patients and health care providers (HCPs), social assistance for IMD-patients and analysing the transition landscape within Europe.Results:The MetabERN structure enables bundling of expertise, capacity building and knowledge transfer for faster diagnosis and better health care. Rare metabolic RMDs are present in all SNWs that require unique treatments according to their metabolic pathways. Implementation of social science to assess the psycho-socio-economic burden of IMDs is still underused. Involvement of patient representatives is essential for a holistic healthcare not only focusing on clinical care, but also on the quality of life for IMD-patients. Surveys identified unmet needs of patient care, patients having little information on national support systems and structural deficits of healthcare systems to ensure HCP can provide adequate clinical care during transition phases. These results are collected by MetabERN and forwarded to the Directorate-General for Health and Food Safety (DG SANTE) of the European Commission (EC) to be addressed further.Conclusion:MetabERN offers an infrastructure of virtual healthcare for patients with IMDs. Thus, in collaboration with ERN ReCONNET, MetabERN can assist in identifying rare metabolic disorders of RMDs to shorten the odyssey of diagnosis and advise on their respective therapies. On the other hand, MetabERN can benefit from EULAR’s longstanding experience regarding issues affecting the quality of life, all RMD patients are facing, such as pain, stiffness, fatigue, rehabilitation, maintaining work and disability claims.References:[1]IEMbase - Inborn Errors of Metabolism Knowledgebase http://www.iembase.org/ (accessed Jan 29, 2021).[2]MetabERN: European Refence Network for Hereditary Metabolic Disorders https://metab.ern-net.eu/ (accessed Jan 29, 2021).[3]Lampe, C.; Dionisi-Vici, C.; Bellettato, C. M.; Paneghetti, L.; van Lingen, C.; Bond, S.; Brown, C.; Finglas, A.; Francisco, R.; Sestini, S.; Heard, J. M.; Scarpa, M.; MetabERN collaboration group. The Impact of COVID-19 on Rare Metabolic Patients and Healthcare Providers: Results from Two MetabERN Surveys. Orphanet J. Rare Dis.2020, 15 (1), 341. https://doi.org/10.1186/s13023-020-01619-x.Acknowledgements:The authors thank the MetabERN collaboration group, the single point of contacts (SPOC) of the MetabERN patient board and the Transition Project Working Group (TPWG)Disclosure of Interests:None declared


Author(s):  
Bruno Machado Agostinho ◽  
Fellipe Bratti Pasini ◽  
Fernanda Oliveira Gomes ◽  
Alex Sandro Roschildt Pinto ◽  
Mario Antonio Ribeiro Dantas

2016 ◽  
Vol 28 (3) ◽  
pp. 481-498 ◽  
Author(s):  
Tatiana Anisimova

Purpose – The purpose of this paper is to test the effects of corporate brand symbolism on consumer satisfaction and loyalty on a sample of Australian automobile consumers. Design/methodology/approach – Survey research was employed to test the study hypotheses. The regression analysis was used to evaluate the relationships between an independent variable (corporate brand symbolism) and dependent variables (consumer satisfaction and loyalty). Findings – Support was found for all hypotheses formulated in this study. Regression results reveal consistent favourable and significant effects of corporate brand symbolism on both consumer satisfaction and loyalty. Research limitations/implications – Although this paper makes contributions in international marketing, the cross-sectional nature of the data collection method limits the information gained to the single point in time. This research studied the impact of corporate brand symbolism on consumers of one original equipment manufacturers (OEM). Having a larger number of participating car manufacturers/OEMs would have provided a wider insight. However, time and resources limitation did not allow to study a larger sample. In the future, practitioners are recommended to further understand the relationship between self and social aspects of brand symbolism in order to formulate more targeted communication strategies. Practical implications – The findings of this study point to the strategic role of the brand in generating both satisfaction and loyalty. In the light of increasing advertising costs and decreasing consumer loyalty, strengthening corporate brand symbolism makes a lot of economic sense. The findings suggest that managers need to take into account consumer need for identity expression and consider this in their branding strategies. Social implications – Humans are social beings by nature. However, international brand research has paid relatively little attention to how products are used by consumers in everyday life, including their social life. Consumer behaviours increasingly depend on social meanings they imbue brands with beyond products’ functional utility. It is argued the focus of symbolic consumption needs to be broadened and integrated more with social science concepts. Originality/value – This study captures a construct of corporate brand symbolism by including self and social aspects of symbolism. The current study also comprehensively measures consumer loyalty, including cognitive, affective and behavioural types of loyalty.


Sign in / Sign up

Export Citation Format

Share Document