DocumentCode :
3598444
Title :
A scheme of distributed hop-count filtering of traffic
Author :
Wang, Xia ; Li, Ming ; Li, Muhai
Author_Institution :
Dept. Computer Sci., Zaozhuang University Shandong 277160, China
fYear :
2009
Firstpage :
516
Lastpage :
521
Abstract :
Distributed Denial of Service (DDOS) remains a threat to exhaust network bandwidth and host resources. Majority of DDOS attack tools utilize IP Spoofing technology that makes it very difficult to filter illegimate packets from aggregated traffic. Contrast to easy forgery of source IP address in the IP header, Time-to-Live (TTL) value is steady relatively. Based on this observation, Wang [1] proposed a scheme called hop-count filtering (HCF) for filtering illegimate packets from aggregated traffic. Wang´s HCF is located in an end-system. In this paper, we introduce a method called distributed HCF (DHCF). Different from [1], DHCF is put in an intermediate-system. It has the advantage for resolving the problems of network bandwidth jam and host resources exhaustion. Comparing the performances of DHCF to HCF on the platform of NS2, our experiments exhibit that DHCF has better performance to relax network jam and maintain normal users´ access.
Keywords :
DDOS; IP spoofing; distributed hop-count Filtering; hop-count Filtering;
fLanguage :
English
Publisher :
iet
Conference_Titel :
Wireless Mobile and Computing (CCWMC 2009), IET International Communication Conference on
Type :
conf
Filename :
5521962
Link To Document :
بازگشت