• DocumentCode
    423217
  • Title

    Tackling congestion to address distributed denial of service: a push-forward mechanism

  • Author

    Krishnamoorthy, Srinivasan ; Dasgupta, Partha

  • Author_Institution
    Dept. of Comput. Sci. & Eng., Arizona State Univ., Tempe, AZ, USA
  • Volume
    4
  • fYear
    2004
  • fDate
    29 Nov.-3 Dec. 2004
  • Firstpage
    2055
  • Abstract
    Distributed denial of service attacks prevent legitimate users from accessing a target machine or the service a target machine provides. One common method of attack is overwhelming the target machine with a large volume of traffic. Thus, handling congestion indirectly leads to detection and recovery from distributed denial of service attacks. The Internet is an interconnected collection of autonomous systems. Every host on an autonomous system connects to the Internet through an access router. Monitoring the rate of packets to and from a host, at the access router, helps in identifying distributed denial of service attacks initiated at the host. Monitoring every access router leads to an effective distributed denial of service prevention, but is infeasible. An alternative is a combination of access router monitoring and intermediate router monitoring with a novel push-forward mechanism that provides good defense within manageable deployment requirements. Push-forward messages reduce the amount of traffic to monitor at the intermediate routers. Prototype testing and simulations of such a combination reveal good congestion detection and recovery time with very little performance overhead.
  • Keywords
    Internet; telecommunication congestion control; telecommunication network routing; telecommunication security; telecommunication traffic; Internet; access router monitoring; autonomous systems; congestion detection; congestion handling; distributed denial of service; intermediate router monitoring; network security; push-forward mechanism; recovery time; Computer crime; Filtering; Internet; Logic; Monitoring; Security; Telecommunication traffic; Testing; Traffic control; Virtual prototyping;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Global Telecommunications Conference, 2004. GLOBECOM '04. IEEE
  • Print_ISBN
    0-7803-8794-5
  • Type

    conf

  • DOI
    10.1109/GLOCOM.2004.1378373
  • Filename
    1378373