• DocumentCode
    2521099
  • Title

    A redirection-based defense mechanism against flood-type attacks in large-scale ISP networks

  • Author

    Hamano, Takafumi ; Suzuki, Ryoichi ; Ikegawa, Takashi ; Ichikawa, Hiroyuki

  • Author_Institution
    NTT Network Service Syst. Labs., NTT Corp., Tokyo, Japan
  • Volume
    2
  • fYear
    2004
  • fDate
    29 Aug.-1 Sept. 2004
  • Firstpage
    543
  • Abstract
    When DoS/DDoS and/or worm attacks occur, it is necessary for Internet service providers to filter out the attack packets and thus provide the users with high data-transmission quality. We propose a defense mechanism based on traffic redirection in which the edge and border routers divert suspicious packets to central defense nodes (C-DNs). For defense in large-scale networks, this is superior to conventional mechanisms such as pushback in terms of operating costs, because the required number of defense nodes is small. In the proposed redirection-based defense mechanism, tunnels are set up between all edge/ border routers and the C-DNs, and the packets destined for victims are diverted to the C-DNs by configuring the policy-based routing rules of the edge and border routers. We compare four techniques using tunneling in traffic-redirection and clarify the advantages of the proposed mechanism for defense in large-scale networks. We also evaluate the reduction in the required number of defense nodes: a reduction in the 25-60% range is possible with large networks.
  • Keywords
    Internet; computer viruses; data communication; telecommunication network routing; telecommunication traffic; C-DN; DoS-DDoS; Internet service provider; border router; central defense node; distributed denial of service; edge router; flood-type attack; high data-transmission; large-scale ISP network; policy-based routing; redirection-based defense mechanism; traffic redirection; worm attack; Information filtering; Information filters; Intelligent networks; Large-scale systems; Mobile communication; Monitoring; Routing; Spine; Telecommunication traffic; Web and internet services;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Communications, 2004 and the 5th International Symposium on Multi-Dimensional Mobile Communications Proceedings. The 2004 Joint Conference of the 10th Asia-Pacific Conference on
  • Print_ISBN
    0-7803-8601-9
  • Type

    conf

  • DOI
    10.1109/APCC.2004.1391773
  • Filename
    1391773