• DocumentCode
    2314741
  • Title

    A Proactive Statistical Defense Solution for DDOS Attacks in Active Networks

  • Author

    Jayashree, P. ; Easwarakumar, K.S. ; Anandharaman, V. ; Aswin, K. ; Raja Vijay, S.

  • Author_Institution
    Dept. of inf. Technol., Anna Univ., Chennai
  • fYear
    2008
  • fDate
    16-18 July 2008
  • Firstpage
    878
  • Lastpage
    881
  • Abstract
    A distributed denial of service attack is coordinated and synchronized set of comprehensive attacks on a sophisticated network and its services that hampers the network infrastructure thereby bringing down its performance. Its effects are characterized by the uninformed delays and interruptions accompanied by undue losses. Since no optimal methodology exists, the internet continues to remain susceptible to DDoS attacks. The PacketScore scheme is a practical DDoS defense mechanism, which approximates the authenticity of the packets concerning its attribute values and discards selective attack packets. This paper extends the PacketScore scheme and implements a new two-level filtering mechanism using leaky bucket that can lessen the losses created by the attacks. The proposed scheme validates the data signatures of the packets complementing the check performed on the packet header. This two-level scrutiny enhances the correctness of detection of DDoS attacks. A standard model to review the efficiency of the two-level filtering has been proposed and the scheme has been deployed and tested in ANTS active network tool kit. The implementation of the proposed scheme is easy let alone efficient and effective in DDoS attack detection with an accurate response to varying DDoS attacks.
  • Keywords
    security of data; statistical analysis; DDOS attacks; PacketScore scheme; active networks; data signatures; distributed denial of service attack; leaky bucket; network infrastructure; packet header; proactive statistical defense solution; two-level filtering mechanism; Communication system traffic control; Computer crime; Detection algorithms; Filtering; Information technology; Internet; Protocols; Sampling methods; Telecommunication traffic; Traffic control;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Emerging Trends in Engineering and Technology, 2008. ICETET '08. First International Conference on
  • Conference_Location
    Nagpur, Maharashtra
  • Print_ISBN
    978-0-7695-3267-7
  • Electronic_ISBN
    978-0-7695-3267-7
  • Type

    conf

  • DOI
    10.1109/ICETET.2008.184
  • Filename
    4580026