Neighbor Stranger Discrimination: A New Defense Mechanism Against Internet DDoS Attacks

被引:0
|
作者
Itani, Sleiman [1 ]
Aaraj, Najwa [1 ]
Abdelahad, Darine [1 ]
Kayssi, Ayman [1 ]
机构
[1] Amer Univ Beirut, Fac Engn & Architecture, Dept Elect & Comp Engn, Beirut, Lebanon
关键词
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Distributed Denial of Service (DDoS) attacks have become a real threat to the security of the Internet. Defending against DDoS is a challenging job, due to the use of IP spoofing and the destination-based routing of the Internet. Many solutions have been proposed, but none is able to completely stop an intense attack. In this paper we propose a new defense mechanism, Neighbor Stranger Discrimination (NSD), which is capable of stopping or significantly reducing the intensity of a DDoS attack. NSD can be incrementally deployed and satisfactory results are achieved even when it is implemented on a small percentage, 10% to 20%, of the Internet routers. The overhead of installing NSD on a certain router is low in terms of additional storage and processing load. Unlike other defense strategies, NSD produces no false positives while reducing false negatives. Being router-based, NSD also stops reflected DDoS attacks (RDDoS) since it discards the spoofed packets before they reach the reflectors.
引用
收藏
页数:6
相关论文
共 50 条
  • [1] A Responsive Defense Mechanism Against DDoS Attacks
    Mosharraf, Negar
    Jayasumana, Anura P.
    Ray, Indrakshi
    FOUNDATIONS AND PRACTICE OF SECURITY (FPS 2014), 2015, 8930 : 347 - 355
  • [2] Simulation of Internet DDoS attacks and defense
    Kotenko, Igor
    Ulanov, Alexander
    INFORMATION SECURITY, PROCEEDINGS, 2006, 4176 : 327 - 342
  • [3] MSOM: Efficient Mechanism for Defense against DDoS Attacks in VANET
    Al-Mehdhara, Mohammed
    Ruan, Na
    WIRELESS COMMUNICATIONS & MOBILE COMPUTING, 2021, 2021
  • [4] A new and comprehensive taxonomy of DDoS attacks and defense mechanism
    Asosheh, Abbass
    Ramezani, Naghmeh
    PROCEEDINGS OF THE 6TH WSEAS INTERNATIONAL CONFERENCE ON INFORMATION SECURITY AND PRIVACY (ISP '07): ADVANCED TOPICS IN INFORMATION SECURITY AND PRIVACY, 2007, : 178 - 183
  • [5] Unified defense against DDoS attacks
    Muthuprasanna, M.
    Manimaran, C.
    Wang, Z.
    NETWORKING 2007: AD HOC AND SENSOR NETWORKS, WIRELESS NETWORKS, NEXT GENERATION INTERNET, PROCEEDINGS, 2007, 4479 : 1047 - +
  • [6] A collaborative defense mechanism against DDoS attacks for network service continuity
    Park, PyungKoo
    Yoo, Seongmin
    Ryu, Hoyong
    Park, Jaehyung
    Chung, Kyung-Ho
    Ryou, Jaecheol
    ASIA LIFE SCIENCES, 2015, : 93 - 107
  • [7] SDNScore: A Statistical Defense Mechanism Against DDoS Attacks in SDN Environment
    Kalkan, Kubra
    Gur, Gurkan
    Alagoz, Fatih
    2017 IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS (ISCC), 2017, : 669 - 675
  • [8] FlowGuard: An Intelligent Edge Defense Mechanism Against IoT DDoS Attacks
    Jia, Yizhen
    Zhong, Fangtian
    Alrawais, Arwa
    Gong, Bei
    Cheng, Xiuzhen
    IEEE INTERNET OF THINGS JOURNAL, 2020, 7 (10): : 9552 - 9562
  • [9] A Distributed Collaborative Entrance Defense Framework Against DDoS Attacks on Satellite Internet
    Guo, Wei
    Xu, Jin
    Pei, Yukui
    Yin, Liuguo
    Jiang, Chunxiao
    Ge, Ning
    IEEE INTERNET OF THINGS JOURNAL, 2022, 9 (17) : 15497 - 15510
  • [10] Joint application and network defense against DDoS flooding attacks in the future Internet
    Karrer, Roger P.
    Kuehn, Ulrich
    Huehn, Thomas
    FGCN: PROCEEDINGS OF THE 2008 SECOND INTERNATIONAL CONFERENCE ON FUTURE GENERATION COMMUNICATION AND NETWORKING, VOLS 1 AND 2, 2008, : 9 - +