• DocumentCode
    1868290
  • Title

    Packetscore: statistics-based overload control against distributed denial-of-service attacks

  • Author

    Kim, Yoohwan ; Lau, Wing Cheong ; Chuah, Mooi Choo ; Chao, H. Jonathan

  • Author_Institution
    Dept. of Electr. Eng. & Comput. Sci., Case Western Reserve Univ., Cleveland, OH, USA
  • Volume
    4
  • fYear
    2004
  • fDate
    7-11 March 2004
  • Firstpage
    2594
  • Abstract
    Distributed denial of service (DDoS) attack is a critical threat to the Internet. Currently, most ISPs merely rely on manual detection of DDoS attacks after which offline fine-grain traffic analysis is performed and new filtering rules are installed manually to the routers. The need of human intervention results in poor response time and fails to protect the victim before severe damages are realized. The expressiveness of existing filtering rules is also too limited and rigid when compared to the ever-evolving characteristics of the attacking packets. Recently, we have proposed a DDoS defense architecture that supports distributed detection and automated on-line attack characterization. We focus on the design and evaluation of the automated attack characterization, selective packet discarding and overload control portion of the proposed architecture. Our key idea is to prioritize packets based on a per-packet score which estimates the legitimacy of a packet given the attribute values it carries. Special considerations are made to ensure that the scheme is amenable to high-speed hardware implementation. Once the score of a packet is computed, we perform score-based selective packet discarding where the dropping threshold is dynamically adjusted based on (1) the score distribution of recent incoming packets and (2) the current level of overload of the system.
  • Keywords
    Internet; statistics; telecommunication congestion control; telecommunication network routing; telecommunication security; telecommunication traffic; Internet; automated on-line attack characterization; distributed denial-of-service attack; distributed detection; dropping threshold; offline fine-grain traffic analysis; packetscore; router; selective packet discarding; statistics-based overload control; Automatic control; Computer crime; Delay; Distributed control; Humans; Information filtering; Information filters; Performance analysis; Protection; Web and internet services;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    INFOCOM 2004. Twenty-third AnnualJoint Conference of the IEEE Computer and Communications Societies
  • ISSN
    0743-166X
  • Print_ISBN
    0-7803-8355-9
  • Type

    conf

  • DOI
    10.1109/INFCOM.2004.1354679
  • Filename
    1354679