Title :
DLimiter: Mitigating Distributed Denial of Service by Using Multiple Discipline Queues
Author :
Campo Giralte, Luis ; Martin de Diego, Isaac ; Conde, Cristina ; Cabello, Enrique
Author_Institution :
Rey Juan Carlos Univ., Madrid, Spain
Abstract :
A distributed denial of service (DDoS) attack is similar to a DoS attack except for the fact that the DDoS attack is launched from multiple hosts, hence the name distributed. A DDoS attack is more effective than a DoS attack and is much more difficult to detect and mitigate due to the distributed nature of its attacks. In this paper, we propose a low-cost system called DLimiter (DDoS Limiter). Its architecture can mitigate those attacks in which links near the target see their bandwidth exhausted before host resources. This is achieved using a hybrid low-cost router-based solution. It is a hybrid solution in the sense that it uses both router-based rate-limiting functions and Honey pot functionalities. Our main goal is to provide uninterrupted service to regular users (someone who makes a proper use of the server´s resources) during a DDoS attack. The system is based on a variable multi-queue discipline and works with linear and exponential queues that change depending on the duration of the attack. The system can also control flow rates just like a Honey pot. It is oriented to multi-core environments and functions at network layer. The system has been evaluated in six different scenarios, using real software and hardware, and the results show that it is able to mitigate the effects of a DDoS attack on regular users.
Keywords :
computer network security; telecommunication network routing; DDoS attack; DDoS-Limiter; DLimiter; Honeypot functionalities; attack duration; bandwidth; control flow rates; distributed denial-of-service attack mitigation; exponential queues; host resources; hybrid low-cost router-based rate-limiting functions; linear queues; multicore environments; multiple discipline queues; network layer; regular users; server resources; uninterrupted service; variable multiqueues; Bandwidth; Computer crime; Delays; IP networks; Instruction sets; Servers; denial of service; queues;
Conference_Titel :
Mechatronics, Electronics and Automotive Engineering (ICMEAE), 2013 International Conference on
Conference_Location :
Morelos
Print_ISBN :
978-1-4799-2252-9
DOI :
10.1109/ICMEAE.2013.29