DocumentCode
3007790
Title
Streaming Algorithms for Robust, Real-Time Detection of DDoS Attacks
Author
Ganguly, Sumit ; Garofalakis, Minos ; Rastogi, Rajeev ; Sabnani, Krishan
Author_Institution
Indian Inst of Tech., Kanpur
fYear
2007
fDate
25-27 June 2007
Firstpage
4
Lastpage
4
Abstract
Effective mechanisms for detecting and thwarting distributed denial-of-service (DDoS) attacks are becoming increasingly important to the success of today\´s Internet as a viable commercial and business tool. In this paper, we propose novel data-streaming algorithms for the robust, real-time detection of DDoS activity in large ISP networks. The key element of our solution is a new, hash-based synopsis data structure for network-data streams that allows us to efficiently track, in guaranteed small space and time, destination IP addresses in the underlying network that are "large" with respect to the number of distinct source IP addresses that have established potentially-malicious (e.g., "half-open") connections to them. Our work is the first to address the problem of efficiently tracking the top distinct-source frequencies over a general stream of updates (insertions and deletions) to the set of underlying network flows, thus enabling us to effectively distinguish between DDoS activity and flash crowds. Preliminary experimental results verify the effectiveness of our approach.
Keywords
IP networks; Internet; cryptography; data structures; IP addresses; ISP networks; Internet; data-streaming algorithms; distributed denial-of-service attacks detection; hash-based synopsis data structure; Business; Computer crime; Data structures; Floods; Frequency; Internet; Monitoring; Network servers; Robustness; TCPIP;
fLanguage
English
Publisher
ieee
Conference_Titel
Distributed Computing Systems, 2007. ICDCS '07. 27th International Conference on
Conference_Location
Toronto, ON
ISSN
1063-6927
Print_ISBN
0-7695-2837-3
Electronic_ISBN
1063-6927
Type
conf
DOI
10.1109/ICDCS.2007.142
Filename
4268161
Link To Document