Distributed packet pairing for reflector based DDoS attack mitigation

被引:15
作者
Al-Duwairi, Basheer [1 ]
Manimaran, G. [1 ]
机构
[1] Iowa State Univ, Dept Elect & Comp Engn, Ames, IA 50011 USA
关键词
network security; DDoS attacks;
D O I
10.1016/j.comcom.2006.03.007
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Reflector based DDoS attacks are feasible in variety of request/reply based protocols including TCP, UDP, ICMP, and DNS. To mitigate these attacks, we advocate the concept of victim assistance and use it in the context of a novel scheme called pairing based filtering (PF). The main idea of the PF scheme is to validate incoming reply packets by pairing them, in a distributed manner, with the corresponding request packets. This pairing is performed at the edge routers of the ISP perimeter that contains the victim rather than at the edge router to which the victim is directly connected, leading to protection from bandwidth exhaustion attacks in addition to the protection from victim's resource exhaustion attacks. We evaluate the proposed scheme through analytical studies using two performance metrics, namely, the probability of allowing an attack packet into the ISP network, and the probability of filtering a legitimate packet. Our analysis shows that the proposed scheme offers a high filtering rate for attack traffic, while causing negligible collateral damage to legitimate traffic. (c) 2006 Elsevier B.V. All rights reserved.
引用
收藏
页码:2269 / 2280
页数:12
相关论文
共 31 条
  • [1] ALDUWAIRI B, 2004, P 10 IEEE INT C PAR
  • [2] ALDUWAIRI B, 2004, P IFIP TC6 NETW C AT
  • [3] [Anonymous], 2003, P ACM C COMP COMM SE
  • [4] [Anonymous], 2000, P 2000 ACM SIGCOMM C
  • [5] SPACE/TIME TRADE/OFFS IN HASH CODING WITH ALLOWABLE ERRORS
    BLOOM, BH
    [J]. COMMUNICATIONS OF THE ACM, 1970, 13 (07) : 422 - &
  • [6] Burch H, 2000, USENIX ASSOCIATION PROCEEDINGS OF THE FOURTEENTH SYSTEMS ADMINISTRATION CONFERENCE (LISA XIV), P319
  • [7] DEAN D, 2001, NETW DISTR SYST SEC
  • [8] Gibson S, 2002, DISTRIBUTED REFLECTI
  • [9] GOODRICH MT, 2002, P ACM CCS 2002 NOV
  • [10] HSU F, 2003, P IEEE INT C DISTR C