Title :
Reconfigurable bandwidth controller for responding the DDoS attacks using token bucket mechanism
Author :
Park, Sang-Kil ; Oh, Jin-Tae ; Kim, Ki-Young ; Jang, Jong-Soo
Author_Institution :
Security Gateway Syst. Team, Electron. & Telecommun. Res. Inst.
Abstract :
Nowadays BcN is researched and developed for supporting the service e-commerce, telecommunication and ubiquitous computing. Internet gives us the benefit of remote access to the information but causes the attacks that can break the server and modify the information. Since 2000 Nimda, code red virus and DDoS attacks are actuated in Internet. This attack programs makes tremendously traffic packet on the Internet. In this paper, we designed and developed the bandwidth controller and packet response coordinator which makes decision and transmit or drop the packet in the gateway systems for the bandwidth consuming attack. This bandwidth controller is implemented in hardware chipset (FPGA) Virtex II Pro which is produced by Xilinx and act as a policing function. We referenced the TBF (token bucket filter) in Linux Kernel 2.4 and implemented this function in HDL (hardware description language) Verilog. This HDL code is synthesized in hardware chipset and performs the Gigabit traffic in real time. This policing function can throttle the traffic as the bandwidth controlling bps speed
Keywords :
Internet; Linux; bandwidth allocation; field programmable gate arrays; hardware description languages; internetworking; telecommunication control; telecommunication security; telecommunication traffic; velocity control; 2000 Nimda; FPGA; Gigabit traffic; Internet; Linux Kernel 2.4; Verilog; Virtex II Pro; bandwidth consuming attack; bps speed control; code red virus; denial of service; e-commerce; gateway systems; hardware chipset; hardware description language; packet response coordinator; policing function; reconfigurable bandwidth controller; remote access; server; telecommunication; token bucket filter; token bucket mechanism; traffic packet; ubiquitous computing; Bandwidth; Communication system traffic control; Computer crime; Control systems; Field programmable gate arrays; Hardware design languages; Internet; Telecommunication control; Ubiquitous computing; Web server;
Conference_Titel :
Advanced Communication Technology, 2005, ICACT 2005. The 7th International Conference on
Conference_Location :
Phoenix Park
DOI :
10.1109/ICACT.2005.245877