• DocumentCode
    545511
  • Title

    A collaborative approach to facilitate intrusion detection and response against DDoS attacks.

  • Author

    Zargar, Saman Taghavi ; Joshi, J.B.D.

  • Author_Institution
    University of Pittsburgh, PA
  • fYear
    2010
  • fDate
    9-12 Oct. 2010
  • Firstpage
    1
  • Lastpage
    8
  • Abstract
    Intrusion detection and response systems (IPSs) for protecting against distributed denial-of-service (DDoS) attacks will beneflit significantly if all the routers within each autonomous system (AS) are capable of detection and response in addition to sampling. However, DDoS detection and response will incur high storage and processing overhead if each router does redundant detection and response tasks. Many overlay communication protocols have been introduced in the literature to achieve coordination among the routers but they generally have high communication overheads. Furthermore, DDoS detection and response requires that all the flows intended to the same destination be analyzed together in order to efficiently capture the correlation between them. In order to do that, current approaches centrally collect all the sampled data and analyze them, which also increases the communication overhead. In this paper, we present a collaborative approach to distribute the sampling, detection, and response responsibilities among all the routers within the AS in such a way that each router can detect and respond to DDoS attacks. Our proposed approach achieves coordination among all the routers in the network to eliminate redundant sampling, detection, and response tasks without exploiting any specific communication protocol. We propose an optimal assignment of disjoint flows to each of the routers within the ASs in such a way that all the flows destined for the same host will be sampled, analyzed, and properly responded at the same router. Each router can thus capture the correlation between flows destined for a specific destination.
  • Keywords
    Access control; Benchmark testing; Cloud computing; Loading; Organizational aspects; Organizations; Network security; Intrusion detection systems; DDoS attacks; distributed IDS; collaborative IDS;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Collaborative Computing: Networking, Applications and Worksharing (CollaborateCom), 2010 6th International Conference on
  • Conference_Location
    Chicago, IL, USA
  • Print_ISBN
    978-963-9995-24-6
  • Type

    conf

  • Filename
    5766993