DocumentCode :
2259288
Title :
Engineering of a global defense infrastructure for DDoS attacks
Author :
Wan, Kalman K K ; Chang, Rocky K C
Author_Institution :
Dept. of Comput., Hong Kong Polytech. Univ., Kowloon, China
fYear :
2002
fDate :
2002
Firstpage :
419
Lastpage :
427
Abstract :
Distributed denial-of-service (DDoS) attacks have emerged as a major threat to the stability of the Internet. By the very nature of the DDoS attacks, pure preventive and pure reactive approaches are not effective to defend against them. We propose a global defense infrastructure to detect-and-respond to the DDoS attacks. This infrastructure consists of a network of distributed local detection systems (LDSes), which detect attacks and respond to them cooperatively. Because of the current Internet topology, this infrastructure can be very effective even if only a small number of major backbone ISPs participate in this infrastructure by installing fully configured LDSes. Moreover, we propose to use traffic volume anomaly for DDoS attack detection. A fully configured LDS monitors the passing traffic for an abnormally high volume of traffic destined to an IP host. A DDoS attack is confirmed if multiple LDSes have detected such anomalies at the same time. Our simulation studies have demonstrated that the proposed detection algorithms are responsive and effective in curbing DDoS attacks.
Keywords :
Internet; digital simulation; network topology; performance evaluation; security of data; telecommunication security; telecommunication traffic; DDoS attack detection; Internet stability; Internet topology; backbone ISP; coordinated attack sources; detection algorithms; distributed attack sources; distributed denial-of-service attacks; distributed local detection systems; e-commerce sites; global defense infrastructure; performance evaluation; simulation; traffic volume anomaly; Computer crime; Detection algorithms; Distributed computing; Filtering; Internet; Kalman filters; Network topology; Spine; Stability; Traffic control;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Networks, 2002. ICON 2002. 10th IEEE International Conference on
Print_ISBN :
0-7803-7533-5
Type :
conf
DOI :
10.1109/ICON.2002.1033348
Filename :
1033348
Link To Document :
بازگشت