DocumentCode
2313218
Title
A Three-Layer Defense Mechanism Based on WEB Servers Against Distributed Denial of Service Attacks
Author
Wu, Zhijun ; Chen, Zhifeng
Author_Institution
Tianjin Key Lab for Adv. Signal Process., Civil Aviation Univ. of China, Tianjin
fYear
2006
fDate
25-27 Oct. 2006
Firstpage
1
Lastpage
5
Abstract
It is widely recognized that distributed denial of service (DDoS) attacks can disrupt Web service and cause large revenue losses. However, effective defenses continue to be mostly unavailable. We design a novel DDoS security mechanism, which is a three-layer defense mechanism based on Web servers. Combining the characteristic of the traffic of Web servers and aiming at TCP/IP reference model, it utilizes the means of statistical filtering and traffic limit in the network layer, transport layer and application layer to filter the illegitimate traffic to secure the pass of the normal traffic. A majority of illegitimate traffic is filtered by the algorithm of SHCF (simplified hop count filtering) on network layer. The rest of illegitimate traffic is filtered by the algorithm of SYN proxy firewall on transmission layer. And traffic limit is used on the application layer for DDoS attacks using legitimate IP. By the collaborative defense of the three-layer mechanism, sustaining availability of Web services can be ensured under DDoS attacks. The defense mechanism is implemented and tested inside the Linux kernel. The result indicates that the three-layer defense mechanism can defend DDoS attacks effectively.
Keywords
Internet; authorisation; filtering theory; statistical analysis; telecommunication security; telecommunication services; telecommunication traffic; transport protocols; DDoS security mechanism; Linux kernel; SYN proxy firewall; TCP/IP reference model; Web servers; Web services; application layer; distributed denial of service attacks; illegitimate traffic filtering; large revenue losses; legitimate IP; network layer; simplified hop count filtering; statistical filtering; three-layer defense mechanism; traffic limit; transmission layer; transport layer; Collaboration; Computer crime; Filtering algorithms; Information filtering; Information filters; TCPIP; Telecommunication traffic; Traffic control; Web server; Web services; DDoS defense; TTL; Web servers; illegitimate traffic;
fLanguage
English
Publisher
ieee
Conference_Titel
Communications and Networking in China, 2006. ChinaCom '06. First International Conference on
Conference_Location
Beijing
Print_ISBN
1-4244-0463-0
Electronic_ISBN
1-4244-0463-0
Type
conf
DOI
10.1109/CHINACOM.2006.344851
Filename
4149816
Link To Document