A Real-Time DDoS Attack Detection and Prevention System Based on per-IP Traffic Behavioral Analysis

被引:0
作者
Zhang, Yi [1 ]
Liu, Qiang [1 ]
Zhao, Guofeng [1 ]
机构
[1] Chongqing Univ Posts & Telecommun, Coll Commun & Informat Engn, Chongqing, Peoples R China
来源
ICCSIT 2010 - 3RD IEEE INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND INFORMATION TECHNOLOGY, VOL 2 | 2010年
关键词
DDoS; real-time; traffic behavior; CUSUM algorithm; Early Stage;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
While many offline-based detection approaches have been well studied, the on-line detection of DDoS attack at leaf router near victims still poses quite a challenge to network administrators. Based on per-IP traffic behavioral analysis, this paper presents a real-time DDoS attack detection and prevention system which can be deployed at the leaf router to monitor and detect DDoS attacks. The advantages of this system lie in its statelessness and low computation overhead, which makes the system itself immune to flooding attacks. Based on the synchronization of TCP and UDP protocol behavior, this system periodically samples every single IP user's sending and receiving traffic and judges whether its traffic behavior meets the synchronization or not. A new non-parametric CUSUM algorithm is applied to detect SYN flooding attacks. Moreover, this system can recognize attackers, victims and normal users, and filter or forward IP packets by means of a quick identification technique. Finally, experiment results show that the system can make a real-time detection for flooding attacks at the early attacking stage, and take effective measures to quench it.
引用
收藏
页码:163 / 167
页数:5
相关论文
共 8 条
  • [1] *ARB NETW, 2008, WORLDW INFR SEC REP
  • [2] Li X., 2006, IMC
  • [3] Survey of network-based defense mechanisms countering the DoS and DDoS problems
    Peng, Tao
    Leckie, Christopher
    Ramamohanarao, Kotagiri
    [J]. ACM COMPUTING SURVEYS, 2007, 39 (01)
  • [4] Ringerg H., 2007, SIGMETRICS
  • [5] Sengar Hemant, 2009, IEEE IWQOS 2009
  • [6] Sommer Robin., 2003, CCS
  • [7] Wang Haining., 2002, IEEE INFOCOM 2002
  • [8] Traflow: Design and complementation of a real time Traffic Measurement System in High-Speed Networks
    Xu Chuan
    Tang Hong
    Zhao Guofeng
    [J]. 2008 IFIP INTERNATIONAL CONFERENCE ON NETWORK AND PARALLEL COMPUTING, PROCEEDINGS, 2008, : 341 - +