DocumentCode :
2578923
Title :
A mitigation model for TCP SYN flooding with IP spoofing
Author :
Kavisankar, L. ; Chellappan, C.
Author_Institution :
Dept. of CSE, Anna Univ., Chennai, India
fYear :
2011
fDate :
3-5 June 2011
Firstpage :
251
Lastpage :
256
Abstract :
DDoS attack is considered to be a major threat among security problems in today´s Internet. These kinds of attack are potentially severe. They bring down business of company drastically. DDoS attack can easily exhaust the computing and communication resources of its victim within a short period of time. There are attacks exploiting some vulnerability or implementation bug in the software implementation of a service, to bring the server down. Some attacks will use all the available resources at the target machine. This paper deals on attacks that consume all the bandwidth available to the victim machine. While concentrating on the bandwidth attack the TCP SYN flood is the more prominent attack. TCP/IP protocol suite is the most widely used protocol suite for data communication. The TCP SYN flood works by exhausting the TCP connection queue of the host and thus denying legitimate connection requests. There are various methods used to detect and prevent this attack, one of which is to block the packet based on SYN flag count from the same IP address. This kind of prevention methods becomes unsuitable when the attackers use the Spoofed IP address. For the prevention of this kind of attacks, the TCP specific probing is used in the proposed scheme where the client is requested to change the windows size/ cause packet retransmission while sending the ACK in the three way hand shake. This is very useful to find the Spoofed IP Packets/TCP SYN flood and preventing them.
Keywords :
Internet; client-server systems; computer network security; cryptographic protocols; data communication; transport protocols; user interfaces; DDoS attack; Internet security problems; SYN flag; Spoofed IP address; TCP SYN flooding; TCP connection queue; TCP/IP protocol suite; bandwidth attack; communication resources; company business; computing resources; data communication; legitimate connection requests; mitigation model; packet retransmission; server; software service implementation; target machine; victim machine; vulnerability; windows; Computer crime; Fingerprint recognition; Floods; IP networks; Probes; Protocols; Servers; DDoS; IP Spoofing; TCP SYN flooding; TCP probing;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Recent Trends in Information Technology (ICRTIT), 2011 International Conference on
Conference_Location :
Chennai, Tamil Nadu
Print_ISBN :
978-1-4577-0588-5
Type :
conf
DOI :
10.1109/ICRTIT.2011.5972435
Filename :
5972435
Link To Document :
بازگشت