DocumentCode :
401146
Title :
Defeating distributed denial-of-service attack with deterministic bit marking
Author :
Kim, Yoohwan ; Jo, Ju-Yeon ; Merat, Frank L.
Author_Institution :
Dept. of Electr. Eng. & Comput. Sci., Case Western Reserve Univ., Cleveland, OH, USA
Volume :
3
fYear :
2003
fDate :
1-5 Dec. 2003
Firstpage :
1363
Abstract :
Distributed denial-of-service (DDoS) attack is a serious threat in Internet. We propose a bit marking concept to identify and drop the DDoS attack packets. Bit marking is a variation of the packet marking technique that modifies packet headers at each router. However instead of storing the router information in the packets, bit marking alters one or more bits in the marking field. The bit marking process discussed in this paper is performed to all the packets and at all the routers along the path; hence it is called deterministic bit marking (DBM). DBM creates a common path signature for all the packets originating from the same location upon arriving at a destination. Since different source networks generate virtually unique path signatures, DBM makes it possible to isolate and discard DDoS attack traffic. From the Internet topology of autonomous systems we observe that the source networks are quite uniformly distributed over the path signature space. In our simulation over 99% of the attack traffic is blocked using DBM while up to 99% of the legitimate traffic passes. DBM can also be used for source traceback using reverse bit marking. DBM can be independently deployed for each ISP and the DBM-based networks can be protected from the attacks coming from nonDBM networks.
Keywords :
Internet; network topology; packet switching; ISP; Internet; Internet topology; autonomous systems; common path signature; deterministic bit marking; distributed denial-of-service attack; packets; router information; Bandwidth; Computer crime; Filtering; IP networks; Internet; Network servers; Network topology; Protection; Telecommunication traffic; Traffic control;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Global Telecommunications Conference, 2003. GLOBECOM '03. IEEE
Print_ISBN :
0-7803-7974-8
Type :
conf
DOI :
10.1109/GLOCOM.2003.1258461
Filename :
1258461
Link To Document :
بازگشت