• DocumentCode
    3207438
  • Title

    IP traceback-based intelligent packet filtering: a novel technique for defending against Internet DDoS attacks

  • Author

    Sung, Minho ; Xu, Jun

  • Author_Institution
    Coll. of Comput., Georgia Inst. of Technol., Atlanta, GA, USA
  • fYear
    2002
  • fDate
    12-15 Nov. 2002
  • Firstpage
    302
  • Lastpage
    311
  • Abstract
    Distributed denial of service (DDoS) is one of the most difficult security problems to address. While many existing techniques (e.g., IP traceback) focus on tracking the location of the attackers after-the-fact, little is done to mitigate the effect of an attack while it is raging on. We present a novel technique that can effectively filter out the majority of DDoS traffic, thus improving the overall throughput of the legitimate traffic. The proposed scheme leverages on and generalizes the IP traceback schemes to obtain the information concerning whether a network edge is on the attacking path of an attacker ("infected") or not ("clean"). We observe that while an attacker will have all the edges on its path marked as "infected", edges on the path of a legitimate client will mostly be "clean". By preferentially filtering out packets that are inscribed with the marks of "infected" edges, the proposed scheme removes most of the DDoS traffic while affecting legitimate traffic only slightly. Simulation results based on real-world network topologies (e.g., Skitter) all demonstrate that the proposed technique can improve the throughput of legitimate traffic by 3 to 7 times during DDoS attacks.
  • Keywords
    Internet; digital simulation; encoding; network topology; security of data; telecommunication network routing; telecommunication security; telecommunication traffic; transport protocols; DDoS traffic filtering; IP traceback-based intelligent packet filtering; Internet DDoS attacks; distributed denial of service; encoding; enhanced probabilistic module; infected edges; legitimate traffic; network edge; perimeter router model; real-world network topologies; security problem; simulation results; throughput; Computer crime; Distributed computing; Educational institutions; Information filtering; Information filters; Security; Telecommunication traffic; Throughput; Traffic control; Web and internet services;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Network Protocols, 2002. Proceedings. 10th IEEE International Conference on
  • ISSN
    1092-1648
  • Print_ISBN
    0-7695-1856-7
  • Type

    conf

  • DOI
    10.1109/ICNP.2002.1181417
  • Filename
    1181417