• DocumentCode
    3598444
  • Title

    A scheme of distributed hop-count filtering of traffic

  • Author

    Wang, Xia ; Li, Ming ; Li, Muhai

  • Author_Institution
    Dept. Computer Sci., Zaozhuang University Shandong 277160, China
  • fYear
    2009
  • Firstpage
    516
  • Lastpage
    521
  • Abstract
    Distributed Denial of Service (DDOS) remains a threat to exhaust network bandwidth and host resources. Majority of DDOS attack tools utilize IP Spoofing technology that makes it very difficult to filter illegimate packets from aggregated traffic. Contrast to easy forgery of source IP address in the IP header, Time-to-Live (TTL) value is steady relatively. Based on this observation, Wang [1] proposed a scheme called hop-count filtering (HCF) for filtering illegimate packets from aggregated traffic. Wang´s HCF is located in an end-system. In this paper, we introduce a method called distributed HCF (DHCF). Different from [1], DHCF is put in an intermediate-system. It has the advantage for resolving the problems of network bandwidth jam and host resources exhaustion. Comparing the performances of DHCF to HCF on the platform of NS2, our experiments exhibit that DHCF has better performance to relax network jam and maintain normal users´ access.
  • Keywords
    DDOS; IP spoofing; distributed hop-count Filtering; hop-count Filtering;
  • fLanguage
    English
  • Publisher
    iet
  • Conference_Titel
    Wireless Mobile and Computing (CCWMC 2009), IET International Communication Conference on
  • Type

    conf

  • Filename
    5521962