Neighbor Stranger Discrimination: A New Defense Mechanism Against Internet DDoS Attacks

被引:0
|
作者
Itani, Sleiman [1 ]
Aaraj, Najwa [1 ]
Abdelahad, Darine [1 ]
Kayssi, Ayman [1 ]
机构
[1] Amer Univ Beirut, Fac Engn & Architecture, Dept Elect & Comp Engn, Beirut, Lebanon
关键词
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Distributed Denial of Service (DDoS) attacks have become a real threat to the security of the Internet. Defending against DDoS is a challenging job, due to the use of IP spoofing and the destination-based routing of the Internet. Many solutions have been proposed, but none is able to completely stop an intense attack. In this paper we propose a new defense mechanism, Neighbor Stranger Discrimination (NSD), which is capable of stopping or significantly reducing the intensity of a DDoS attack. NSD can be incrementally deployed and satisfactory results are achieved even when it is implemented on a small percentage, 10% to 20%, of the Internet routers. The overhead of installing NSD on a certain router is low in terms of additional storage and processing load. Unlike other defense strategies, NSD produces no false positives while reducing false negatives. Being router-based, NSD also stops reflected DDoS attacks (RDDoS) since it discards the spoofed packets before they reach the reflectors.
引用
收藏
页数:6
相关论文
共 50 条
  • [21] Global Orchestration of Cooperative Defense against DDoS Attacks for MEC
    Tan, Xinrui
    Li, Hongjia
    Wang, Liming
    Xu, Zhen
    2019 IEEE WIRELESS COMMUNICATIONS AND NETWORKING CONFERENCE (WCNC), 2019,
  • [22] Distributed and Predictive-Preventive Defense Against DDoS Attacks
    Jog, Manjiri
    Natu, Maitreya
    Shelke, Sushama
    PROCEEDINGS OF THE 16TH INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING AND NETWORKING, 2015,
  • [23] METHODOLOGIES FOR EVALUATING GAME THEORETIC DEFENSE AGAINST DDOS ATTACKS
    Khirwadkar, Tanmay
    Nguyen, Kien C.
    Nicol, David M.
    Basar, Tamer
    PROCEEDINGS OF THE 2010 WINTER SIMULATION CONFERENCE, 2010, : 697 - 707
  • [24] gore:: Routing-assisted defense against DDoS attacks
    Chou, ST
    Stavrou, A
    Ioannidis, J
    Keromytis, AD
    INFORMATION SECURITY, PROCEEDINGS, 2005, 3650 : 179 - 193
  • [25] A distributed filtering mechanism against DDoS attacks: ScoreForCore
    Kalkan, Kubra
    Alagoz, Fatih
    COMPUTER NETWORKS, 2016, 108 : 199 - 209
  • [26] Two Layer Defending Mechanism against DDoS Attacks
    Subramanian, Kiruthika
    Gunasekaran, Preetha
    Selvaraj, Mercy
    INTERNATIONAL ARAB JOURNAL OF INFORMATION TECHNOLOGY, 2015, 12 (04) : 317 - 324
  • [27] DAD: Domain Adversarial Defense System Against DDoS Attacks in Cloud
    Divyasree, I. R.
    Selvamani, K.
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2022, 19 (01): : 554 - 568
  • [28] IoT standard platform architecture that provides defense against DDoS attacks
    Lee, Yun-kyung
    Kim, Young-ho
    Kim, Jeong-nyeo
    2021 IEEE INTERNATIONAL CONFERENCE ON CONSUMER ELECTRONICS-ASIA (ICCE-ASIA), 2021,
  • [29] TDFA: Traceback-based Defense against DDoS Flooding Attacks
    Foroushani, Vahid Aghaei
    Zincir-Heywood, A. Nur
    2014 IEEE 28TH INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS (AINA), 2014, : 597 - 604
  • [30] On an Integrated Security Framework for Defense Against Various DDoS Attacks in SDN
    Wu, Hao
    Hou, Aiqin
    Nie, Weike
    Wu, Chase
    2023 INTERNATIONAL CONFERENCE ON COMPUTING, NETWORKING AND COMMUNICATIONS, ICNC, 2023, : 311 - 317