Title :
Deployable overlay network for defense against distributed SYN flood attacks
Author :
Ohsita, Yuichi ; Ata, Shingo ; Murata, Masayuki
Author_Institution :
Graduate Sch. of Inf. Sci. & Technol., Osaka Univ., Japan
Abstract :
Distributed denial-of-service attacks on public servers have recently become more serious. To assure that network services will not be interrupted, we need faster and more accurate defense mechanisms against malicious traffic, especially SYN floods. But single point defense (ex. firewalls) lacks a scalability to catch up the increase of the attack traffic. In this paper, we introduce a distributed defense mechanism using overlay networks. This mechanism detects attacks near the victim servers and alert messages are sent via the overlay networks. Then defense nodes identify legitimate traffic and block malicious ones. The legitimate traffic is protected via the overlay networks. We simulate and verify our proposed method can effectively block malicious traffic and protect legitimate traffic. We also describe the deployment scenario of our defense mechanism.
Keywords :
Internet; authorisation; network servers; telecommunication security; telecommunication traffic; transport protocols; TCP proxy; defense mechanism; denial-of-service attack; distributed SYN flood attack; distributed legitimate traffic protection; overlay network deployment; public server; Computer crime; Electronic mail; Floods; IP networks; Information science; Network servers; Protection; Scalability; Telecommunication traffic; Traffic control;
Conference_Titel :
Computer Communications and Networks, 2005. ICCCN 2005. Proceedings. 14th International Conference on
Print_ISBN :
0-7803-9428-3
DOI :
10.1109/ICCCN.2005.1523897