**Comparative Study Based on DoS Attack in Wired and Wireless Network at Physical Layer in MANET**

Ahmad Yusri Dak<sup>1</sup>\*, Norfarina Nordin<sup>2</sup>,

<sup>1,2,3</sup> Faculty of Computer and Mathematical Sciences, Universiti Teknologi MARA Perlis branch, Arau, 02600, Perlis

Corresponding author: ahmadyusri@uitm.edu.my

Received Date: \*date

Accepted Date: \*date

ABSTRACT

*Denial of Service (DoS) attack has become one of the major threats to the Internet. Generally, attackers launch DoS attacks by directing a number of attack sources to send useless traffic to the victim. The victim’s services are disrupted when its host or network resources are occupied by the attack traffic. The threat of DoS attacks has become even more severe as attackers can compromise a huge number of computers by spreading a computer worm using vulnerabilities in popular operating systems. A survey conducted by the Malaysian Computer Emergency Response Team (MYCERT) Malaysia 2018, the past ten years shown a significant increase of DoS attack up to 20% since 2007. These attacks are done either from wired environment or from the wireless environment. Riverbed Modeler Academic Edition 17.5 and Wireshark Analyser 2.6.4 is used to design and analyse the performance of the network under DoS attack. A comparison of two scenarios is conducted. The first scenario is DoS attack in wired network and the second is DoS Attack in wireless network. Furthermore, the performance of for each scenario are conducted based on the performance metrics of BER, SNR and throughput. Furthermore, these three performances metrics were analysed and the result concluded BER and SNR unable to detect the attack compared to throughput metric.*

*Keywords: DoS, DDoS, Ping, BER, SNR, Throughput*

# INTRODUCTION 

Nowadays, many organizations preferred to use hybrid network which is combination of wired and wireless technology as a medium to access Internet and Intranet services. Hybrid network infrastructure offers many advantageous such as cost effective, information and infrastructure sharing, and tasks distributed cooperatively through computing resources contributing. However, over last few decades, due to popularity of Internet and wireless network, an illegal act has numerously enlarged within the networks resulting in the extension of devious and malicious contents particularly flooding based on DoS attacks that is known to be troublesome attacks (Thakur, 2015). With the increasing of sophisticated networking technology such as high-end switch and router, DoS attacks are getting harder to detect specifically at network and application layers. Data recorded by the Malaysian Computer Emergency Response Team (MYCERT) Malaysia 2019, shown a significant increase of flooding-based DoS attack up to 20% since 2007. One of major concern is lack of knowledge in detection mechanism among system administrator that contributed to this statistic. Therefore, a comprehensive study of detection metrics, characteristics attack against wired and wireless network is proposed to study the pattern of attack.

Two types of scenario which consists of wired and wireless network are designed and developed using Riverbed Modeler simulator and Wireshark network analyzer. Each of scenario is tested to disrupted networks by injecting rubbish packets namely Ping of Death (PoDs) attack which is part of DoS attack. Three detection metrics are proposed to identify attack; Bit Error Rate (BER), Signal to Noise Ratio (SNR) and throughput. Thus, similar experiment to be conducted by physically cutting wiring or preventing power and cooling resources from being accessed. This trend is quite devastating due to implementation of hybrid network.

**RELATED WORK  
**

The DoS attack have a severe impact on computer networks for past few decades. Researchers conduct intensive simulations to analyze the performance of their designed networks in the presence of these attacks and investigate how to mitigate against them.

(Kshirsagar et al., 2016) suggested and applied detection mechanism for efficient detection of DoS LAND attack. The suggested detection mechanism architecture consists of network traffic analyser, feature identification and extraction, the IP spoofing based on attack detection and intrusion information module (Kshirsagar et al., 2016). The efficient detection of DoS LAND attack is primarily based on IP spoofing. The results show that memory and CPU utilization is increased during the occurrence of attack and minimized effectively during the detection of DoS LAND attack. In addition, (Guo & Lee, 2010) investigate Distributed Denial of Service (DDoS) attacks using Non-Address-Spoofing Flood (NASF) over MANETs. Detection features based on statistical analysis of IDS log files and flow rate information are proposed and study. The detection of NASF attack is evaluated using three metrics, including detection ratio, detection time and false detection rate. Hence, the proposed framework addresses deal with important issues in forensic science to identify what and when the attack arises. The different NASF attack patterns with different network throughput degradations are simulated and examined in his paper.

Song et al. indicates that a Denial of Service (DoS) detection method based on the collection of interdependent behaviour data in a sensor network environment (Guo & Lee, 2010). In order to collect the interdependent behaviour data, we tend to use a base station to analyse traffic and behaviours amongst nodes. This is to introduce techniques of detecting changes within the environment with precursor symptoms. The study shows a DoS Detection System based on Global Interdependent Behaviours and the results of using the test-bed to detect sensor for the DoS attacks.

Salem et al. showed that we are able to predict the network firewall activities ahead of time using forecasting techniques such as Holt-Winter or Linear Regression(Song et al., 2010) . The anomalies representing the DoS pattern are described within the previous sections. It does display a solid relationship between the patterns obtained from the past and future logs data by investigating the difference. However, the maximum allowed average of rejected packets counts needs to be determined in a percentage format as different networks operate under different levels of inbound data traffic per hour in order to be applied to other network environments.

Farooq et al. has discussed that a few Dos attacks in wireless sensor networks and how they affecting the network and defence against them and list up some detection techniques, which would help the user to recognize the techniques which have been proposed in recent year and in what way new techniques may be designed (Salem & Armstrong, 2008). The new detection scheme’s result indicates a guaranteed pattern at the intermediate level. Consequently, the positive result functions to aid the users to recognize the existing techniques over the recent years and design improved future designs.

# SIMULATION SCENARIO

The network topology of the two scenarios: DoS attack in wired network and for DoS attack in wireless network are shown in Figures 2, 3 and 4, respectively.

![](131-1-409-1-4-20200925_media/media/image1.png)

Figure 1. Topology of Simulation Scenario

![](131-1-409-1-4-20200925_media/media/image2.png)

Figure 2. Network Topology of DoS attack in Wired network

![](131-1-409-1-4-20200925_media/media/image3.png)

Figure 3. Network Topology of DoS attack in Wireless network

Figure 2 shows a diagram of network topology of DoS attack in wired network that simulated using OPNET simulation tool. Scenarios are configured as an office network with two departments, Finance and Registrar that are connected remotely over the Internet. It consists of two clients, two switches, a server and an attacker connected to the Internet port(8080). The scenario is configured in form of wired environment that normally implemented in normal office. The activity starts when attacker sends DoS attack by sending rubbish packet to server using ping od death (PoD) command. The command loading the server with huge number of rubbish packets sent continuously by attacker to increase the bandwidth and therefore, clients deny accessing the server. Consequences, the attacks will decrease the processing capacity of the server and bandwidth which result in the DoS attack.

Figure 2 shows a network topology of DoS attack in wireless network. It consists of a victim and an attacker connected to personal hotspot network. The attacker uses a ping command to flood the network with huge number of packets. The operation starts when attackers flood the network with just enough of packets to bring the services down. The operation mimics legitimate traffic and it becomes difficult to distinguish between normal and attacked traffic.

The simulation configured for a duration of thirty minutes to capture the performance metrics of the Bit Error Rate (bytes/sec), Signal-to-Noise Ratio (bytes/sec) and throughput (bytes/sec). Moreover, this performance metrics are measured for the server.

# PERFORMANCE TEST FOR DOS ATTACK IN WIRED NETWORK

In this performance test, DoS attack was attacking the wired network by sending maximum packets to the victim without any delay using Ping of Death. To evaluate the attack, three metrics were used such as BER, SNR and throughput. The scenario with and without DoS attack were compared and presented in next subsection.

### **Performance test using Bit Error Rate(BER)**

![](131-1-409-1-4-20200925_media/media/image4.png)

Figure 4. BER Simulation Scenario

As shown in Figure 4, the graph for DoS attack in wired are presented with two line represented scenario without DoS attack and with DoS attack. Both simulation environments are configured for thirty minutes as in Figure 2. The blue line represents graph scenario without DoS attack and the red line represents scenario with DoS attack. BER detection in wired network shows a constant of zero bps for both without attack and with attack. The scenario shows that BER unable to detect DoS attack in network layer either for wired scenario. The result in line with study conducted by (Farooq et al., 2014) whereby BER has ability to attack at MAC layer only but not at physical layer.

### **Performance test using Signal-to-Noise Ratio(SNR)**

![](131-1-409-1-4-20200925_media/media/image5.png)

Figure 5. Simulation Scenario for SNR

As presented in Figure 5, the scenario of BER configured using DoS attack in wired network and tested for thirty minutes. The graph with y-axis is labelled as SNR value while x-axis is labelled as time per second. The graph with blue line represents the scenario without DoS attack and red line represents the scenario with DoS attack. The scenario also showed the constant straight line zero bps of SNR value in the period thirty minutes.Therefore, the result represent that SNR unable tp detect the DoS attack due to the packets are sent and received 100% by receiver without noise generate in between sender and receiver. This shown by value of zero bps for both scenarios.

### **Performance test using throughput**

![](131-1-409-1-4-20200925_media/media/image6.png)

Figure 6. Simulation Scenario for throughput

From Figure 6, the graph with line y-axis labelled as throughput in bps and the graph with line x-axis is labelled as time per second. The blue line represented as the graph of without DoS attack simulation and the red line represented as the graph with DoS attack that is simulate using OPNET simulation tool. The result of simulation scenarios show that the throughput is the ability to detect DoS attack in wired network. Throughput the ability to detect DoS attack at wired network due to failure of packets transmission in the network. This result show that the simulation with DoS attack allowed more throughput because there are interruptions between the transmission of the packets.

## PERFORMANCE TEST FOR DOS ATTACK IN WIRELESS NETWORK

In wireless network performance test, DoS attack was configured to attackwireless network by sending maximum packets to the victim without any delay as recommended by (Sarkar & Member, 2011). **In order to** evaluate the attack, three metrics were used. The scenario with DoS attack and without DoS attack were compared as in Figure 3.

### **Performance test using Bit Error Rate (BER)**

![](131-1-409-1-4-20200925_media/media/image7.png)

Figure 7. Simulation Scenario for BER

Figure 7 shows result of BER DoS attack in wireless network that have tested in real-time environment. The graph with blue line shows the BER detection without DoS attack through period of 30 minutes. Meanwhile, the red line represents the BER detection with DoS attack. The BER line shows constant zero bps value for without DoS attack and with DoS attack. The graphs show that there is no data collected during the period of 30 minutes. The result shows that BER is unable to detect DoS attack in wireless network because bit transmitted was unable to cannot be detected by BER. This is due to the there is no error bit received due to noise during the transmission of the packets.

### **Performance test using Signal-to-Noise Ratio(SNR)**

![](131-1-409-1-4-20200925_media/media/image8.png)

Figure 8. Simulation Scenario using SNR

As shown in Figure 5, the graph for SNR detection for DoS attack in wireless network is represented. The real-time tes-bed is configured and tested for 30 minutes with two graphs being collected; graph without DoS attack and with DoS attack in wireless network. The graph shows that there is no data collected during 30 minutes simulation. The graph with x-axis is labelled as time per second and y-axis is labelled as SNR value bps. The graph with blue line represents the result for detection of SNR without DoS attack and the line shows that SNR value zero bps in constant straight line. The red line represents the result for detection of SNR value with DoS attack and it also shows that SNR value 0 bps in constant straight line. The value of SNR for both graphs produce constant straight line of zero bps. SNR is unable to detect due to there is no noise generate in between the packets due to the attack. During 30 minutes of simulation, the SNR value 0 bps has been captured for both environment; without DoS attack and with DoS attack in wireless network. A higher SNR value means more distortion in transmission. This means that there is no distortion during the transmission of the packets. Hence, there is no data collected for environment which is without DoS attack and with DoS attack in wireless network.

### **Performance test using throughput**

![](131-1-409-1-4-20200925_media/media/image9.png)

Figure 9. Simulation Scenario for

As shown in Figure 9, the graph for throughput detection for DoS attack in wireless network is presented. The test-bed is configured in real-time environment and tested in 30 minutes. The graph of time was labelled with x-axis and throughput was labelled as y-axis. The blue line which is detection of throughput without DoS attack shows that there is data collected during the period of 30 minutes. Meanwhile, the red line which is detection of throughput with DoS attack also shows that there is data collected during the period of 30 minutes. The detection of throughput with DoS attack shows a result increase and decrease and suddenly fall in straight line in constant of 0 bps. For detection of throughput with DoS attack shows that the result sudden increase in from 0 bps 8078 bps and suddenly it continuously decreasing. This result shows that the data have been delivered in the transmission during 30 minutes of time period.

##### **CONCLUSION**

The performance of the simulated network evaluated in two different scenarios that clearly showed how the DoS attacks affect the smooth operation of Internet-based services. By analyzing standalone and multiple machine attacks, the negative impact of the DoS and the DDoS attacks is examined to show the severe impact on the business operation. This paper demonstrates how the DoS attacks disrupt the smooth business operation of the organization and how the DoS attacks affect the productivity of the business.

Security software, hardware vendors and security researchers should consider to work together to prevent new ways of DoS attacks in the future that can impact the global network structure, government organizations, corporate businesses, and individuals. Collective measures of protection will minimize the impact and reduce the magnitude of the attack. Security administrators should monitor their networks actively to mitigate the threats of the attack and protect networked devices not to be part of the botnet for the use of other attacks.

##### **References**

Farooq, N., Zahoor, I., Mandal, S., & Gulzar, T. (2014). Systematic Analysis of DoS Attacks in Wireless Sensor Networks with Wormhole Injection. *International Journal of Information and Computation Technology*, *4*(2), 173–182. http://www.Guo, Y., & Lee, I. (2010). Forensic analysis of DoS attack traffic in MANET. *Proceedings - 2010 4th International Conference on Network and System Security, NSS 2010*, 293–298. https://doi.org/10.1109/NSS.2010.48Kshirsagar, D., Rathod, A., & Wathore, S. (2016). Performance analysis of DoS LAND attack detection. *Perspectives in Science*, *8*, 736–738. https://doi.org/10.1016/j.pisc.2016.06.074Salem, M., & Armstrong, H. (2008). Identifying DOS attacks using data pattern analysis. *Proceedings of 6th Australian Information Security Management Conference*, *December 2006*, 110–117. https://doi.org/10.4225/75/57b56484b8771Sarkar, N. I., & Member, S. (2011). The Impact of Transmission Overheads on IEEE 802 . 11 Throughput : Analysis and Simulation. *Journal of Selected Areas in Telecommunication (JSAT),* 49–55.Song, J. gu, Jung, S., Kim, J. H., Seo, D. Il, & Kim, S. (2010). Research on a Denial of Service (DoS) detection system based on global interdependent behaviors in a sensor network environment. *Sensors (Switzerland)*, *10*(11), 10376–10386. https://doi.org/10.3390/s101110376Thakur, K. (2015). Analysis of Denial of Services ( DOS ) Attacks and Prevention Techniques. *International Journal of Engineering Research & Technology (IJERT)*, *4*(Jul).
