Engineering of a global defense infrastructure for DDoS attacks

K.K.K. Wan1, R.K.C. Chang1
1Department of Computing, Hong Kong Polytechnic University, Hong Kong, China

Tóm tắt

Distributed denial-of-service (DDoS) attacks have emerged as a major threat to the stability of the Internet. By the very nature of the DDoS attacks, pure preventive and pure reactive approaches are not effective to defend against them. We propose a global defense infrastructure to detect-and-respond to the DDoS attacks. This infrastructure consists of a network of distributed local detection systems (LDSes), which detect attacks and respond to them cooperatively. Because of the current Internet topology, this infrastructure can be very effective even if only a small number of major backbone ISPs participate in this infrastructure by installing fully configured LDSes. Moreover, we propose to use traffic volume anomaly for DDoS attack detection. A fully configured LDS monitors the passing traffic for an abnormally high volume of traffic destined to an IP host. A DDoS attack is confirmed if multiple LDSes have detected such anomalies at the same time. Our simulation studies have demonstrated that the proposed detection algorithms are responsive and effective in curbing DDoS attacks.

Từ khóa

#Computer crime #Traffic control #Internet #Filtering #Kalman filters #Distributed computing #Stability #Network topology #Spine #Detection algorithms

Tài liệu tham khảo

wan, 2001, An Infrastructure to Defend Against Disributed Denial of Service Attack 10.1145/383059.383060 10.1109/CSAC.1998.738566 porras, 0, EMERALD Event Monitoring Enabling Responses to Anomalous Live Disturbances, Proc Natl Information Systems Security Conference Oct 1997 savage, 0, Practical Network Support for IP Traceback, Proc ACM SIGCOMM Aug 2000 0, The Network Simulator-ns-2 10.1145/383059.383061 1996, CERT Advisory CA-96 01 UDP Port Denial-of-Service Attack 2000, Internet Denial of Service Attacks and the Federal Response 10.1109/CSAC.1998.738563 feinstein, 2002, Intrusion Detection criscuolo, 0 0, The Common Intrusion Detection Framework Architecture 2000, CERT Advisory CA-98 01 smurf IP denial-of-service attacks 1996, CERT Advisory CA-96 21 TCP SYN Flooding and IP Spoofing Attacks 10.1109/6294.869381 curry, 2001, Intrusion detection message exchange format data model and extensible markup language (XML) document type definition