DocumentCode :
1181592
Title :
Early detection and prevention of denial-of-service attacks: a novel mechanism with propagated traced-back attack blocking
Author :
Haggerty, John ; Shi, Qi ; Merabti, Madjid
Author_Institution :
Sch. of Comput. & Math. Sci., Liverpool John Moores Univ., UK
Volume :
23
Issue :
10
fYear :
2005
Firstpage :
1994
Lastpage :
2002
Abstract :
A major threat to the information economy is denial-of-service (DoS) attacks. These attacks are highly prevalent despite the widespread deployment of perimeter-based countermeasures. Therefore, more effective approaches are required to counter the threat. This requirement has motivated us to propose a novel, distributed, and scalable mechanism for effective early detection and prevention of DoS attacks at the router level within a network infrastructure. This paper presents the design details of the new mechanism. Specifically, this paper shows how the mechanism combines both stateful and stateless signatures to provide early detection of DoS attacks and, therefore, protect the enterprise network. More importantly, this paper discusses how a domain-based approach to an attack response is used by the mechanism to block attack traffic. This novel approach enables the blockage of an attack to be gradually propagated only through affected domains toward the attack sources. As a result, the attack is eventually confined within its source domains, thus avoiding wasteful attack traffic overloading the network infrastructure. This approach also provides a natural way of tracing back the attack sources, without requiring the use of specific trace-back techniques and additional resources for their implementation.
Keywords :
Internet; authorisation; business communication; digital signatures; telecommunication network routing; telecommunication traffic; DoS; denial-of-service; denial-of-service attack prevention; distributed scalable mechanism; domain-based approach; early detection; enterprise network; information economy; network security; overloading traffic; perimeter-based counter-measure; propagated traced-back attack blocking; router level; stateful signature; stateless signature; threat counter; Availability; Computer crime; Counting circuits; Data security; Helium; Information security; Internet; Protection; Protocols; Telecommunication traffic; Denial-of-service (DoS); distributed detection; security;
fLanguage :
English
Journal_Title :
Selected Areas in Communications, IEEE Journal on
Publisher :
ieee
ISSN :
0733-8716
Type :
jour
DOI :
10.1109/JSAC.2005.854123
Filename :
1514528
Link To Document :
بازگشت