DocumentCode :
429510
Title :
Port hopping for resilient networks
Author :
Lee, Henry C J ; Thing, Vrizlynn L L
Author_Institution :
Inst. for Infocomm Res., Singapore, Singapore
Volume :
5
fYear :
2004
fDate :
26-29 Sept. 2004
Firstpage :
3291
Abstract :
With the pervasiveness of the Internet, denial-of-service (DoS) and distributed DoS (DDoS) attacks have become important threats to servers, hosts and devices that are connected. The paper addresses the problem of mitigating DoS/DDoS attacks so as to ensure that legitimate traffic is given an acceptable level of quality of service. We propose a new technique, called port hopping, where the UDP/TCP port number used by the server varies as a function of time and a shared secret between the server and the client. The main strength of the mechanism lies in the simplification of both the detection and filtering of malicious attack packets and that it does not require any change to existing protocols. This port hopping technique is compatible with UDP and TCP and can be implemented using socket communications for UDP, and for setting up TCP communications. We performed both a theoretical analysis and empirical studies through an actual implementation to study the effectiveness of the scheme against DoS/DDoS flooding attacks. Our experiments show that the port hopping technique is effective in detecting and filtering malicious traffic, and hence improves the reliability of good traffic flow.
Keywords :
Internet; computer network reliability; quality of service; security of data; telecommunication security; telecommunication traffic; transport protocols; Internet; QoS; TCP; UDP; denial-of-service attacks; distributed DoS attacks; flooding attacks; malicious traffic detection; port hopping; port number; quality of service; resilient networks; shared secret; socket communications; Computer crime; Filtering; Internet; Network servers; Performance analysis; Protocols; Quality of service; Sockets; Telecommunication traffic; Web server;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Vehicular Technology Conference, 2004. VTC2004-Fall. 2004 IEEE 60th
ISSN :
1090-3038
Print_ISBN :
0-7803-8521-7
Type :
conf
DOI :
10.1109/VETECF.2004.1404672
Filename :
1404672
Link To Document :
بازگشت