Neighbor Stranger Discrimination: A New Defense Mechanism Against Internet DDoS Attacks

被引:0
|
作者
Itani, Sleiman [1 ]
Aaraj, Najwa [1 ]
Abdelahad, Darine [1 ]
Kayssi, Ayman [1 ]
机构
[1] Amer Univ Beirut, Fac Engn & Architecture, Dept Elect & Comp Engn, Beirut, Lebanon
关键词
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Distributed Denial of Service (DDoS) attacks have become a real threat to the security of the Internet. Defending against DDoS is a challenging job, due to the use of IP spoofing and the destination-based routing of the Internet. Many solutions have been proposed, but none is able to completely stop an intense attack. In this paper we propose a new defense mechanism, Neighbor Stranger Discrimination (NSD), which is capable of stopping or significantly reducing the intensity of a DDoS attack. NSD can be incrementally deployed and satisfactory results are achieved even when it is implemented on a small percentage, 10% to 20%, of the Internet routers. The overhead of installing NSD on a certain router is low in terms of additional storage and processing load. Unlike other defense strategies, NSD produces no false positives while reducing false negatives. Being router-based, NSD also stops reflected DDoS attacks (RDDoS) since it discards the spoofed packets before they reach the reflectors.
引用
收藏
页数:6
相关论文
共 50 条
  • [31] Filtering-Based Defense Mechanisms Against DDoS Attacks: A Survey
    Kalkan, Kubra
    Gur, Gurkan
    Alagoz, Fatih
    IEEE SYSTEMS JOURNAL, 2017, 11 (04): : 2761 - 2773
  • [32] SmartDefense: A distributed deep defense against DDoS attacks with edge computing
    Myneni, Sowmya
    Chowdhary, Ankur
    Huang, Dijiang
    Alshamrani, Adel
    COMPUTER NETWORKS, 2022, 209
  • [33] Perimeter-based defense against high bandwidth DDoS attacks
    Chen, SG
    Song, QG
    IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2005, 16 (06) : 526 - 537
  • [34] A Hybrid Defense Mechanism for DDoS attacks using Cluster Analysis in MANET
    Devi, P.
    Kannammal, A.
    PROCEEDINGS OF THE 2012 INTERNATIONAL CONFERENCE ON ADVANCES IN COMPUTING, COMMUNICATIONS AND INFORMATICS (ICACCI'12), 2012, : 287 - 291
  • [35] A comprehensive taxonomy of DDoS attacks and defense mechanism applying in a smart classification
    Asosheh, Abbass
    Ramezani, Naghmeh
    WSEAS Transactions on Computers, 2008, 7 (04): : 281 - 290
  • [36] A path identification mechanism for effective filtering against DDoS attacks
    Ahn, Y
    Wee, K
    Hong, M
    8TH WORLD MULTI-CONFERENCE ON SYSTEMICS, CYBERNETICS AND INFORMATICS, VOL III, PROCEEDINGS: COMMUNICATION AND NETWORK SYSTEMS, TECHNOLOGIES AND APPLICATIONS, 2004, : 325 - 330
  • [37] A dynamic path identification mechanism to defend against DDoS attacks
    Lee, G
    Lim, H
    Hong, M
    Lee, DH
    INFORMATION NETWORKING: CONVERGENCE IN BROADBAND AND MOBILE NETWORKING, 2005, 3391 : 806 - 813
  • [38] A Pi2HC Mechanism against DDoS Attacks
    Jin, Guang
    Li, Yuan
    Zhang, Huizhan
    Qian, Jiangbo
    2008 THIRD INTERNATIONAL CONFERENCE ON COMMUNICATIONS AND NETWORKING IN CHINA, VOLS 1-3, 2008, : 215 - 219
  • [39] RCS: A distributed mechanism against link flooding DDoS attacks
    Cui, Yong
    Song, Lingjian
    Xu, Ke
    INFORMATION NETWORKING: ADVANCES IN DATA COMMUNICATIONS AND WIRELESS NETWORKS, 2006, 3961 : 764 - +
  • [40] Pi: A path identification mechanism to defend against DDoS attacks
    Yaar, A
    Perrig, A
    Song, D
    2003 IEEE SYMPOSIUM ON SECURITY AND PRIVACY, PROCEEDINGS, 2003, : 93 - 107