Title :
A Novel DDoS Attack Defending Framework with Minimized Bilateral Damages
Author :
Chen, Yu ; Ku, Wei-Shinn ; Sakai, Kazuya ; DeCruze, Christopher
Author_Institution :
Dept. of Electr. & Comput. Eng., SUNY Binghamton, Binghamton, NY, USA
Abstract :
Distributed Denial of Service (DDoS) attacks are one of the most damaging threats against Internet based applications. Many of the DDoS defense mechanisms may unintentionally deny a certain portion of legitimate user accesses by mistaking them as attackers or may simply not block enough traffic to adequately protect the victim. Other better performing systems have not yet to reach adoption because of designs that require a substantial investment into the Internet infrastructure before offering much effectiveness. This paper proposes Heimdall, a novel traffic verification based framework to protect legitimate traffic from bilateral damages. Based on a proof-of-work technique and application of distributed hash ID, aside from protecting established connections, our system can validate new initial request for communication and open valid channels between users and the protected server. Through intensive simulation experiments on the ns-2 network simulator, we verified that Heimdall scheme can effectively protect legitimate communications and filter out malicious flows with very high accuracy.
Keywords :
Internet; computer network security; telecommunication traffic; DDoS attack defending framework; Heimdall; Internet; bilateral damage minimization; communication channel; distributed denial of service; distributed hash ID; legitimate communications; legitimate traffic; legitimate user access; ns-2 network simulator; open valid channel; proof-of-work technique; protected server; traffic verification based framework; Communications Society; Computer crime; Computer networks; Filters; Investments; Peer to peer computing; Protection; Telecommunication traffic; Traffic control; Web and internet services;
Conference_Titel :
Consumer Communications and Networking Conference (CCNC), 2010 7th IEEE
Conference_Location :
Las Vegas, NV
Print_ISBN :
978-1-4244-5175-3
Electronic_ISBN :
978-1-4244-5176-0
DOI :
10.1109/CCNC.2010.5421853