DocumentCode :
3295866
Title :
MAFIC: adaptive packet dropping for cutting malicious flows to push back DDoS attacks
Author :
Chen, Yu ; Kwok, Yu-Kwong ; Hwang, Kai
Author_Institution :
Univ. of Southern California, Los Angeles, CA, USA
fYear :
2005
fDate :
6-10 June 2005
Firstpage :
123
Lastpage :
129
Abstract :
In this paper, we propose a new approach called MAFIC (malicious flow identification and cutoff) to support adaptive packet dropping to fend off DDoS attacks. MAFIC works by judiciously issuing lightweight probes to flow sources to check if they are legitimate. Through such probing, MAFIC would drop malicious attack packets with high accuracy while minimizes the loss on legitimate traffic flows. Our NS-2 based simulation indicates that MAFIC algorithm drops packets from unresponsive potential attack flows with an accuracy as high as 99% and reduces the loss of legitimate flows to less than 3%. Furthermore, the false positive and negative rates are low-only around 1% for a majority of the cases.
Keywords :
Internet; packet switching; telecommunication network routing; telecommunication security; telecommunication traffic; DDoS attacks; MAFIC; NS-2 based simulation; adaptive packet dropping; duplicated ACK; malicious flow identification and cutoff; Computer crime; Contracts; Councils; Information filtering; Information filters; Internet; Probes; Protection; Telecommunication traffic; Traffic control; DDoS defense; duplicated ACKs; malicious flows; packet dropping policy; probing;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Distributed Computing Systems Workshops, 2005. 25th IEEE International Conference on
Print_ISBN :
0-7695-2328-5
Type :
conf
DOI :
10.1109/ICDCSW.2005.84
Filename :
1437166
Link To Document :
بازگشت