A novel mechanism for detection and prevention of Distributed Denial of Service attacks

被引:0
作者
Lin Pingping [1 ]
Zhang Xiaosong [1 ]
机构
[1] Univ Elect Sci & Technol China, Sch Comp Sci & Engn, Chengdu 610054, Peoples R China
来源
PROCEEDINGS OF THE INTERNATIONAL CONFERENCE INFORMATION COMPUTING AND AUTOMATION, VOLS 1-3 | 2008年
关键词
DDoS; filter; sliding window; trap;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Give a simple but practical scheme for detecting and defending against Distributed Denial of Service (DDoS), especially for Highly Distributed Denial of Service (HDDoS) attacks by monitoring the increase of new IP addresses. Unlike previous proposals, this proposal includes three modules: detecting, filtering, and illegal-packets analyzing. To improve the detection accuracy, we also proposed a simple but robust algorithm: sliding window algorithm. In the filtering module, a filter performs its tasks only during attacks. While the attack-packets-analyzing module uses a trap to analyze attack packets, perfects the defense system. Simulation results demonstrate the effectiveness of the proposed scheme under varieties of DDoS attack scenarios.
引用
收藏
页码:289 / 292
页数:4
相关论文
共 8 条
  • [1] Stateful DDoS attacks and targeted filtering
    Chen, Shigang
    Tang, Yong
    Du, Wenliang
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2007, 30 (03) : 823 - 840
  • [2] Jin C., 2003, CCS '03, P30
  • [3] Kang J, 2006, PROCEEDINGS OF 2006 INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND CYBERNETICS, VOLS 1-7, P2712
  • [4] Peng T, 2004, LECT NOTES COMPUT SC, V3042, P771
  • [5] TAO P, 2003, P ICC 2003 ANCH AL U
  • [6] Defense against spoofed IP traffic using hop-count filtering
    Wang, Haining
    Jin, Cheng
    Shin, Kang G.
    [J]. IEEE-ACM TRANSACTIONS ON NETWORKING, 2007, 15 (01) : 40 - 53
  • [7] Wu NN, 2004, PROCEEDINGS FROM THE FIFTH IEEE SYSTEMS, MAN AND CYBERNETICS INFORMATION ASSURANCE WORKSHOP, P416
  • [8] StackPi: New packet marking and filtering mechanisms for DDoS and IP spoofing defense
    Yaar, Abraham
    Perrig, Adrian
    Song, Dawn
    [J]. IEEE JOURNAL ON SELECTED AREAS IN COMMUNICATIONS, 2006, 24 (10) : 1853 - 1863