Title :
Router based detection for low-rate agents of DDoS attack
Author :
Nashat, Dalia ; Jiang, Xiaohong ; Horiguchi, Susumu
Author_Institution :
Grad. Sch. of Inf. Sci., Tohoku Univ., Tohoku
Abstract :
The TCP SYN flooding attack is the most prevalent type of DDoS attacks that exhaust network resources. The current detection schemes only work well for the detection of high-rate flooding sources. It is notable, however, that in the current DDoS attacks, the flooding rate is usually distributed among many low-rate flooding agents to make the detection more difficult. Therefore, a more sensitive and fast detection scheme is highly desirable for the efficient detection of these low-rate flooding sources. In this paper, we focus on the low-rate agent and propose a router-based detection scheme for it. The proposed scheme is based on the TCP SYN-SYN/ACK protocol pair with the consideration of packet header information (both sequence and Ack. numbers). To make our scheme more sensitive and generally applicable, the counting bloom filter is used to avoid the effect of SYN/ACK retransmission and the change point detection method is applied to avoid the dependence of detection on sites and access patterns. Extensive trace-driven simulation has been conducted to demonstrate the efficiency of the proposed scheme in terms of its detection probability and also average detection time.
Keywords :
security of data; transport protocols; DDoS attack; TCP SYN flooding attack; TCP SYN-SYN-ACK protocol pair; average detection time; change point detection method; counting bloom filter; detection probability; flooding rate; low-rate flooding agents; network resources; packet header information; router based detection; trace-driven simulation; Computer crime; Filters; Floods; Large-scale systems; Protocols; TCPIP;
Conference_Titel :
High Performance Switching and Routing, 2008. HSPR 2008. International Conference on
Conference_Location :
Shanghai
Print_ISBN :
978-1-4244-1981-4
Electronic_ISBN :
978-1-4244-1982-1
DOI :
10.1109/HSPR.2008.4734440