DocumentCode :
813678
Title :
A Divide-and-Conquer Strategy for Thwarting Distributed Denial-of-Service Attacks
Author :
Chen, Ruiliang ; Park, Jung-Min ; Marchany, Randolph
Author_Institution :
Bradley Dept. of Electr. & Comput. Eng., Virginia Polytech. & State Univ., Blacksburg, VA
Volume :
18
Issue :
5
fYear :
2007
fDate :
5/1/2007 12:00:00 AM
Firstpage :
577
Lastpage :
588
Abstract :
Attack mitigation schemes actively throttle attack traffic generated in distributed denial-of-service (DDoS) attacks. This paper presents attack diagnosis (AD), a novel attack mitigation scheme that adopts a divide-and-conquer strategy. AD combines the concepts of pushback and packet marking, and its architecture is in line with the ideal DDoS attack countermeasure paradigm - attack detection is performed near the victim host and packet filtering is executed close to the attack sources. AD is a reactive defense mechanism that is activated by a victim host after an attack is detected. By instructing its upstream routers to mark packets deterministically, the victim can trace back one attack source and command an AD-enabled router close to the source to filter the attack packets. This process isolates one attacker and throttles it, which is repeated until the attack is mitigated. We also propose an extension to AD called parallel attack diagnosis (PAD) that is capable of throttling traffic coming from a large number of attackers simultaneously. AD and PAD are analyzed and evaluated using the Skitter Internet map, Lumeta´s Internet map, and the 6-degree complete tree topology model. Both schemes are shown to be robust against IP spoofing and to incur low false positive ratios
Keywords :
IP networks; Internet; computer crime; divide and conquer methods; telecommunication network routing; telecommunication security; telecommunication traffic; 6-degree complete tree topology model; AD attack mitigation scheme; AD-enabled router; DDoS attack countermeasure paradigm; IP spoofing; Lumeta Internet map; Skitter Internet map; attack detection; distributed denial-of-service attacks; divide-and-conquer strategy; packet marking; parallel attack diagnosis; pushback concept; traffic throttling; Atherosclerosis; Computer crime; Information filtering; Information filters; Internet; Resource management; Robustness; Telecommunication traffic; Topology; Traffic control; Network-level security and protection.;
fLanguage :
English
Journal_Title :
Parallel and Distributed Systems, IEEE Transactions on
Publisher :
ieee
ISSN :
1045-9219
Type :
jour
DOI :
10.1109/TPDS.2007.1014
Filename :
4160927
Link To Document :
بازگشت