DocumentCode
813678
Title
A Divide-and-Conquer Strategy for Thwarting Distributed Denial-of-Service Attacks
Author
Chen, Ruiliang ; Park, Jung-Min ; Marchany, Randolph
Author_Institution
Bradley Dept. of Electr. & Comput. Eng., Virginia Polytech. & State Univ., Blacksburg, VA
Volume
18
Issue
5
fYear
2007
fDate
5/1/2007 12:00:00 AM
Firstpage
577
Lastpage
588
Abstract
Attack mitigation schemes actively throttle attack traffic generated in distributed denial-of-service (DDoS) attacks. This paper presents attack diagnosis (AD), a novel attack mitigation scheme that adopts a divide-and-conquer strategy. AD combines the concepts of pushback and packet marking, and its architecture is in line with the ideal DDoS attack countermeasure paradigm - attack detection is performed near the victim host and packet filtering is executed close to the attack sources. AD is a reactive defense mechanism that is activated by a victim host after an attack is detected. By instructing its upstream routers to mark packets deterministically, the victim can trace back one attack source and command an AD-enabled router close to the source to filter the attack packets. This process isolates one attacker and throttles it, which is repeated until the attack is mitigated. We also propose an extension to AD called parallel attack diagnosis (PAD) that is capable of throttling traffic coming from a large number of attackers simultaneously. AD and PAD are analyzed and evaluated using the Skitter Internet map, Lumeta´s Internet map, and the 6-degree complete tree topology model. Both schemes are shown to be robust against IP spoofing and to incur low false positive ratios
Keywords
IP networks; Internet; computer crime; divide and conquer methods; telecommunication network routing; telecommunication security; telecommunication traffic; 6-degree complete tree topology model; AD attack mitigation scheme; AD-enabled router; DDoS attack countermeasure paradigm; IP spoofing; Lumeta Internet map; Skitter Internet map; attack detection; distributed denial-of-service attacks; divide-and-conquer strategy; packet marking; parallel attack diagnosis; pushback concept; traffic throttling; Atherosclerosis; Computer crime; Information filtering; Information filters; Internet; Resource management; Robustness; Telecommunication traffic; Topology; Traffic control; Network-level security and protection.;
fLanguage
English
Journal_Title
Parallel and Distributed Systems, IEEE Transactions on
Publisher
ieee
ISSN
1045-9219
Type
jour
DOI
10.1109/TPDS.2007.1014
Filename
4160927
Link To Document