A countermeasure against DDOS attacks using active networks technologies

被引:0
|
作者
Kashiwa, D
Chen, EY
Fuji, H
机构
[1] NTT Corp, Informat Sharing Platform Labs, Yokosuka, Kanagawa 2390847, Japan
[2] Keio Univ, Fac Sci & Technol, Tokyo 108, Japan
[3] Univ Tokyo, Tokyo, Japan
关键词
computer security; Internet; congestion control; active telecommunication network; distributed system; adaptive method; automatic classification;
D O I
暂无
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
A Distributed Denial of Service (DDOS) attack consumes the resources of a remote host or network by sending a massive amount of IP packets from many distributed hosts. It is a pressing problem on the Internet as demonstrated by recent attacks on major e-commerce servers and ISPS. Since the attack is distributed and the attack tools evolve at a rapid and alarming rate, an effective solution must be formulated using a distributed and adaptive approach. In this paper we propose a countermeasure against DDOS attacks using a method we call Active Shaping. Our method employs the Active Networks technologies, which incorporates programmability into network nodes. The Active Networks technology enables us to deter congestion and bandwidth consumption of the backbone network caused by DDOS attacks, and to prevent our system from dropping packets of legitimate users mistakenly. This paper introduces the concept of our method, system design and evaluates the effectiveness of our method using a prototype..
引用
收藏
页码:605 / 629
页数:25
相关论文
共 50 条
  • [21] SENSS Against Volumetric DDoS Attacks
    Ramanathan, Sivaramakrishnan
    Mirkovic, Jelena
    Yu, Minlan
    Zhang, Ying
    34TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE (ACSAC 2018), 2018, : 266 - 277
  • [22] A Countermeasure Recommendation System against Targeted Attacks with Preserving Continuity of Internal Networks
    Hasegawa, Hirokazu
    Yamaguchi, Yukiko
    Shimada, Hajime
    Takakura, Hiroki
    2014 IEEE 38TH ANNUAL INTERNATIONAL COMPUTERS, SOFTWARE AND APPLICATIONS CONFERENCE (COMPSAC), 2014, : 400 - 405
  • [23] Accountable File Indexing against DDoS Attacks in Peer-to-Peer Networks
    Lou, Xiaosong
    Hwang, Kai
    Hu, Yue
    GLOBECOM 2009 - 2009 IEEE GLOBAL TELECOMMUNICATIONS CONFERENCE, VOLS 1-8, 2009, : 2504 - +
  • [24] Scheme of defending against DDoS attacks in large-scale ISP networks
    Wu, Zhi-jun
    Zhang, Dong
    NETWORK AND PARALLEL COMPUTING, PROCEEDINGS, 2007, 4672 : 296 - +
  • [25] Securing IoT Networks Against DDoS Attacks: A Hybrid Deep Learning Approach
    Ul Ain, Noor
    Sardaraz, Muhammad
    Tahir, Muhammad
    Abo Elsoud, Mohamed W.
    Alourani, Abdullah
    SENSORS, 2025, 25 (05)
  • [26] Research on the detection and defense systems against DDoS attacks in ad hoc networks
    Jing, Huang
    Wen, Wushao
    INFORMATION SCIENCE AND MANAGEMENT ENGINEERING, VOLS 1-3, 2014, 46 : 1161 - 1167
  • [27] Distributed Intrusion Detection using Mobile Agents against DDoS Attacks
    Akyazi, Ugur
    Uyar, A. Sima Etaner
    23RD INTERNATIONAL SYMPOSIUM ON COMPUTER AND INFORMATION SCIENCES, 2008, : 346 - +
  • [28] Safeguarding IoT networks against DDoS attacks using deep learning based zero trust network access
    Khan, Murad
    ELECTRONICS LETTERS, 2024, 60 (21)
  • [29] Detection of known and unknown DDoS attacks using Artificial Neural Networks
    Saied, Alan
    Overill, Richard E.
    Radzik, Tomasz
    NEUROCOMPUTING, 2016, 172 : 385 - 393
  • [30] Countermeasure for collusion attacks against digital watermarking
    Steinebach, M
    Zmudzinski, S
    SECURITY, STEGANOGRAPHY, AND WATERMARKING OF MULTIMEDIA CONTENTS VIII, 2006, 6072