DocumentCode :
1695829
Title :
RateGuard: A Robust Distributed Denial of Service (DDoS) Defense System
Author :
Sun, Huizhong ; Ngan, Wingchiu ; Chao, H. Jonathan
Author_Institution :
ECE, Polytech. Inst. of NYU, Brooklyn, OH, USA
fYear :
2009
Firstpage :
1
Lastpage :
8
Abstract :
One of the major threats to cyber security is the distributed denial-of-service (DDoS) attack. In this paper, we focus on three kinds of sophisticated DDoS attacks that seriously cripple the current DDoS defense systems and have not been solved yet. In fast adaptive attacks (FAAs), attackers adaptively generate attacking traffic based on the feedback from a victim in round trip time (RTT). Almost all proposed rules-based filtering schemes cannot effectively defend against FAAs, since they need a relatively long time (compared to RTT) to update filtering rules. In adaptive attacks with statistical filtering rules scanning (AAS), attackers circumvent the defense system by discovering the statistical filtering rules of the defense system and then generating flooding traffic to mimic nominal traffic. In low rate TCP attacks (LRAs), attackers send periodic attack pulses to overflow a router´s buffer and force the legitimate TCP flow to a low throughput while staying under the radar with a very low average rate. In this paper, we propose a leaky-bucket (LB) based highly robust DDoS defense system, called RateGuard. It can react to FAAs and LRAs by rate-limiting excessive traffic in real-time according to the victim´s nominal traffic profile. Moreover, by associating an LB with each joint attribute value, the huge space required for possible joint attribute values makes it almost impossible for attackers to scan the victim´s nominal traffic profiles and, thus, makes it highly robust to cope with AAS and other sophisticated attacks.
Keywords :
filtering theory; telecommunication network routing; telecommunication security; telecommunication traffic; transport protocols; DDoS defense system; RateGuard; cyber security; fast adaptive attacks; flooding traffic; low rate TCP attacks; robust distributed denial of service defense system; round trip time; router buffer; rules-based filtering schemes; statistical filtering rules scanning; victim nominal traffic profile; Adaptive filters; Computer crime; Computer security; FAA; Feedback; Filtering; Floods; Radar; Robustness; Throughput;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Global Telecommunications Conference, 2009. GLOBECOM 2009. IEEE
Conference_Location :
Honolulu, HI
ISSN :
1930-529X
Print_ISBN :
978-1-4244-4148-8
Type :
conf
DOI :
10.1109/GLOCOM.2009.5425941
Filename :
5425941
Link To Document :
بازگشت