DocumentCode :
792763
Title :
IP traceback-based intelligent packet filtering: a novel technique for defending against Internet DDoS attacks
Author :
Sung, Minho ; Xu, Jun
Author_Institution :
Coll. of Comput., Georgia Inst. of Technol., Atlanta, GA, USA
Volume :
14
Issue :
9
fYear :
2003
Firstpage :
861
Lastpage :
872
Abstract :
Distributed Denial of Service (DDoS) is one of the most difficult security problems to address. While many existing techniques (e.g., IP traceback) focus on tracking the location of the attackers after-the-fact, little is done to mitigate the effect of an attack while it is raging on. We present a novel technique that can effectively filter out the majority of DDoS traffic, thus improving the overall throughput of the legitimate traffic. The proposed scheme leverages on and generalizes the IP traceback schemes to obtain the information concerning whether a network edge is on the attacking path of an attacker ("infected") or not ("clean"). We observe that, while an attacker will have all the edges on its path marked as "infected," edges on the path of a legitimate client will mostly be "clean". By preferentially filtering out packets that are inscribed with the marks of "infected" edges, the proposed scheme removes most of the DDoS traffic while affecting legitimate traffic only slightly. Simulation results based on real-world network topologies all demonstrate that the proposed technique can improve the throughput of legitimate traffic by three to seven times during DDoS attacks.
Keywords :
Internet; security of data; telecommunication security; telecommunication traffic; transport protocols; Distributed Denial of Service; IP traceback; Internet DDoS attacks; data security; intelligent packet filtering; network topologies; performance modeling; simulation; throughput; Cellular neural networks; Computer crime; Information filtering; Information filters; Network topology; Security; Telecommunication traffic; Throughput; Traffic control; Web and internet services;
fLanguage :
English
Journal_Title :
Parallel and Distributed Systems, IEEE Transactions on
Publisher :
ieee
ISSN :
1045-9219
Type :
jour
DOI :
10.1109/TPDS.2003.1233709
Filename :
1233709
Link To Document :
بازگشت