DocumentCode
3598444
Title
A scheme of distributed hop-count filtering of traffic
Author
Wang, Xia ; Li, Ming ; Li, Muhai
Author_Institution
Dept. Computer Sci., Zaozhuang University Shandong 277160, China
fYear
2009
Firstpage
516
Lastpage
521
Abstract
Distributed Denial of Service (DDOS) remains a threat to exhaust network bandwidth and host resources. Majority of DDOS attack tools utilize IP Spoofing technology that makes it very difficult to filter illegimate packets from aggregated traffic. Contrast to easy forgery of source IP address in the IP header, Time-to-Live (TTL) value is steady relatively. Based on this observation, Wang [1] proposed a scheme called hop-count filtering (HCF) for filtering illegimate packets from aggregated traffic. Wang´s HCF is located in an end-system. In this paper, we introduce a method called distributed HCF (DHCF). Different from [1], DHCF is put in an intermediate-system. It has the advantage for resolving the problems of network bandwidth jam and host resources exhaustion. Comparing the performances of DHCF to HCF on the platform of NS2, our experiments exhibit that DHCF has better performance to relax network jam and maintain normal users´ access.
Keywords
DDOS; IP spoofing; distributed hop-count Filtering; hop-count Filtering;
fLanguage
English
Publisher
iet
Conference_Titel
Wireless Mobile and Computing (CCWMC 2009), IET International Communication Conference on
Type
conf
Filename
5521962
Link To Document