PacketScore:: A statistics-based packet filtering scheme against distributed denial-of-service attacks

被引:78
作者
Kim, Y
Lau, WC
Chuah, MC
Chao, HJ
机构
[1] Univ Nevada, Sch Comp Sci, Las Vegas, NV 89154 USA
[2] Chinese Univ Hong Kong, Dept Informat Engn, Shatin, Hong Kong, Peoples R China
[3] Lehigh Univ, Dept Comp Sci & Engn, Bethlehem, PA 18015 USA
[4] Polytech Univ, Dept Elect & Comp Engn, Brooklyn, NY 11201 USA
关键词
network level security and protection; performance evaluation; traffic analysis; network monitoring; security; simulation;
D O I
10.1109/TDSC.2006.25
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Distributed Denial-of-Service (DDoS) attacks are a critical threat to the Internet. This paper introduces a DDoS defense scheme that supports automated online attack characterizations and accurate attack packet discarding based on statistical processing. The key idea is to prioritize a packet based on a score which estimates its legitimacy given the attribute values it carries. Once the score of a packet is computed, this scheme performs score-based selective packet discarding where the dropping threshold is dynamically adjusted based on the score distribution of recent incoming packets and the current level of system overload. This paper describes the design and evaluation of automated attack characterizations, selective packet discarding, and an overload control process. Special considerations are made to ensure that the scheme is amenable to high-speed hardware implementation through scorebook generation and pipeline processing. A simulation study indicates that PacketScore is very effective in blocking several different attack types under many different conditions.
引用
收藏
页码:141 / 155
页数:15
相关论文
共 29 条
[1]  
[Anonymous], IEEE ACM T NETWORKIN
[2]  
[Anonymous], P IEEE S SEC PRIV
[3]  
[Anonymous], 2003, P ACM C COMP COMM SE
[4]  
[Anonymous], 2000, IETF
[5]  
BABCOCK B, 2002, ACM S PRINC DAT SYST
[6]  
CHUAH MC, 2004, P IEEE INT C COMM
[7]  
*CISCO IOS SEC CON, 12 2 CONF UN REV PAT
[8]  
ESTAN C, 2003, P 2003 C APPL TECHN, P137, DOI DOI 10.1145/863955.863972
[9]  
GARBER L, 2000, DENIAL OF SERVICE AT, P12
[10]  
Ioannidis J., 2002, Implementing pushback: Router-based defense against DDoS attacks