DocumentCode :
1153706
Title :
Active router approach to defeating denial-of-service attacks in networks
Author :
El-Moussa, F.A. ; Linge, N. ; Hope, M.
Author_Institution :
Centre for Networking & Telecommun. Res., Univ. of Salford
Volume :
1
Issue :
1
fYear :
2007
fDate :
2/1/2007 12:00:00 AM
Firstpage :
55
Lastpage :
63
Abstract :
Denial-of-service attacks represent a major threat to modern organisations who are increasingly dependent on the integrity of their computer networks. A new approach to combating such threats introduces active routers into the network architecture. These active routers offer the combined benefits of intrusion detection, firewall functionality and data encryption and work collaboratively to provide a distributed defence mechanism. The paper provides a detailed description of the design and operation of the algorithms used by the active routers and demonstrates how this approach is able to defeat a SYN and SMURF attack. Other approaches to network design, such as the introduction of a firewall and intrusion detection systems, can be used to protect networks, however, weaknesses remain. It is proposed that the adoption of an active router approach to protecting networks overcomes many of these weaknesses and therefore offers enhanced protection
Keywords :
authorisation; computer networks; cryptography; telecommunication network routing; telecommunication security; SMURF attack; SYN attack; active router approach; data encryption; denial-of-service attacks; distributed defence mechanism; firewall functionality; intrusion detection; network architecture;
fLanguage :
English
Journal_Title :
Communications, IET
Publisher :
iet
ISSN :
1751-8628
Type :
jour
DOI :
10.1049/iet-com:20050441
Filename :
4105980
Link To Document :
بازگشت