DocumentCode
459448
Title
A Coordinated Detection and Response Scheme for Distributed Denial-of-Service Attacks
Author
Lam, Ho-Yu ; Li, Chi-Pan ; Chanson, Samuel T. ; Yeung, Dit-Yan
Author_Institution
Department of Computer Science, Hong Kong University of Science and Technology, Clear Water Bay, Kowloon, Hong Kong. ivanlam@cs.ust.hk
Volume
5
fYear
2006
fDate
38869
Firstpage
2165
Lastpage
2170
Abstract
Distributed denial-of-service (DDoS) attacks present serious threats to servers in the Internet. They can exhaust critical resources at a target host with the help of a large number of compromised Internet hosts and hence deny services to legitimate clients. This paper studies some existing schemes for the detection and defense against TCP-based DDoS attacks. We propose a distributed scheme that can mitigate the damage caused by DDoS through a coordinated detection and response framework. This proposed scheme composes of a number of heterogeneous defense systems which cooperate with each other in protecting Internet servers. We have set up a network testbed for carrying out extensive experiments using real server machines, routers and software attack tools. Experimental results show that, compared to existing schemes, our proposed scheme can greatly improve the throughput of legitimate traffic and reduce the attack traffic during DDoS attacks. To investigate the scale-up behavior of our scheme, we have also developed a software simulator for larger-scale experiments. Simulation results show that our scheme performs consistently well even in networks with more than 3000 nodes and under high traffic load.
Keywords
Computer crime; Network servers; Protection; Software testing; Software tools; Telecommunication traffic; Throughput; Traffic control; Web and internet services; Web server;
fLanguage
English
Publisher
ieee
Conference_Titel
Communications, 2006. ICC '06. IEEE International Conference on
Conference_Location
Istanbul
ISSN
8164-9547
Print_ISBN
1-4244-0355-3
Electronic_ISBN
8164-9547
Type
conf
DOI
10.1109/ICC.2006.255091
Filename
4024486
Link To Document