Title :
A source identification scheme against DDoS attacks in cluster interconnects
Author :
Manhee Lee ; Eun Jung Kim ; Cheol Won Lee
Author_Institution :
Texas A&M University
Abstract :
Designing secure clusters has recently become a critical issue to make these systems robust to attacks from the Internet. The Distributed Denial of Service (DDoS) attack is one of the most serious problems in the current Internet. To defend against DDoS attacks, clusters usually depend on firewalls or Intrusion Detection Systems (IDS). However, once firewall and IDS are breached, the impact of DDoS attack within a cluster can be severe. That is because one infected system or one malicious user, which is believed to be trustworthy, may instantly paralyze the whole cluster through the high speed network. In this paper, we present a deterministic distance packet marking (DDPM) scheme to identify the source nodes generating spoofed IP packets in cluster interconnects. The scheme can be applied to many cluster interconnects such as mesh, torus and hypercube, which are popular in many commercial systems. Our scheme is practically attractive since it is scalable to large networks and does not incur much processing overhead on both switches and nodes.
Keywords :
Communication system security; Computer crime; Computer science; Computer security; Computer worms; Data security; High-speed networks; Intrusion detection; Robustness; Telecommunication traffic;
Conference_Titel :
Parallel Processing Workshops, 2004. ICPP 2004 Workshops. Proceedings. 2004 International Conference on
Conference_Location :
Montreal, QC, Canada
Print_ISBN :
0-7695-2198-3
DOI :
10.1109/ICPPW.2004.1328039