DocumentCode
1632064
Title
Countering denial-of-service attacks using congestion triggered packet sampling and filtering
Author
Huang, Yih ; Pullen, J. Mark
Author_Institution
Dept. of Comput. Sci., George Mason Univ., Fairfax, VA, USA
fYear
2001
fDate
6/23/1905 12:00:00 AM
Firstpage
490
Lastpage
494
Abstract
Denial-of-service (DoS) attacks have received a great amount of attention in research communities and general public alike, due to recent, high-profile attacks against major Internet e-commerce sites. We present a countermeasure against such attacks, called the congestion-triggered packet sampling/packet filtering (CTPS/PF) architecture. With CTPS/PF, a packet sampling mechanism that is integrated with the congestion control mechanism at routers is used to detect DoS attacks, and packet filters are activated only when sampling results warrant action. One important concern in deploying any form of traffic analysis in the critical data-forwarding paths of the Internet is performance. Our sample processing algorithm takes into account the confidence indicators of statistic results to raise alarms with relatively small numbers of samples. Moreover, the per-sample processing complexity is only O(1). Our simulation study reveals that the CTPS/PF architecture is able to detect the presence of DoS attacks and take proper action within hundreds of milliseconds to tens of seconds. Moreover, the average sampling overhead during a congestion period is in the vicinity of 1 sample per second
Keywords
Internet; sampling methods; security of data; telecommunication congestion control; telecommunication security; Internet e-commerce sites; congestion triggered packet filtering; congestion triggered packet sampling; data-forwarding paths; denial-of-service attacks; sampling overhead; traffic analysis; Computer crime; Computer science; Electronic mail; Information filtering; Information filters; Internet; Multiprotocol label switching; Performance analysis; Sampling methods; Traffic control;
fLanguage
English
Publisher
ieee
Conference_Titel
Computer Communications and Networks, 2001. Proceedings. Tenth International Conference on
Conference_Location
Scottsdale, AZ
ISSN
1095-2055
Print_ISBN
0-7803-7128-3
Type
conf
DOI
10.1109/ICCCN.2001.956309
Filename
956309
Link To Document