Neighbor Stranger Discrimination: A New Defense Mechanism Against Internet DDoS Attacks

被引:0
|
作者
Itani, Sleiman [1 ]
Aaraj, Najwa [1 ]
Abdelahad, Darine [1 ]
Kayssi, Ayman [1 ]
机构
[1] Amer Univ Beirut, Fac Engn & Architecture, Dept Elect & Comp Engn, Beirut, Lebanon
关键词
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Distributed Denial of Service (DDoS) attacks have become a real threat to the security of the Internet. Defending against DDoS is a challenging job, due to the use of IP spoofing and the destination-based routing of the Internet. Many solutions have been proposed, but none is able to completely stop an intense attack. In this paper we propose a new defense mechanism, Neighbor Stranger Discrimination (NSD), which is capable of stopping or significantly reducing the intensity of a DDoS attack. NSD can be incrementally deployed and satisfactory results are achieved even when it is implemented on a small percentage, 10% to 20%, of the Internet routers. The overhead of installing NSD on a certain router is low in terms of additional storage and processing load. Unlike other defense strategies, NSD produces no false positives while reducing false negatives. Being router-based, NSD also stops reflected DDoS attacks (RDDoS) since it discards the spoofed packets before they reach the reflectors.
引用
收藏
页数:6
相关论文
共 50 条
  • [41] A defense system against DDoS attacks by large-scale IP traceback
    Xiang, Y
    Zhou, WL
    THIRD INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY AND APPLICATIONS, VOL 2, PROCEEDINGS, 2005, : 431 - 436
  • [42] Dolus: Cyber Defense using Pretense against DDoS Attacks in Cloud Platforms
    Neupane, Roshan Lal
    Neely, Travis
    Chettri, Nishant
    Vassell, Mark
    Zhang, Yuanxun
    Calyam, Prasad
    ICDCN'18: PROCEEDINGS OF THE 19TH INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING AND NETWORKING, 2018,
  • [43] A Hybrid Intrusion Detection Architecture for Defense against DDoS Attacks in Cloud Environment
    Gupta, Sanchika
    Horrow, Susmita
    Sardana, Anjali
    CONTEMPORARY COMPUTING, 2012, 306 : 498 - 499
  • [44] An elastic and resiliency defense against DDoS attacks on the critical DNS authoritative infrastructure
    Wang, Zheng
    JOURNAL OF COMPUTER AND SYSTEM SCIENCES, 2019, 99 : 1 - 26
  • [45] Secure Double-layered Defense against HTTP-DDoS Attacks
    Samir, Mohamad
    Aida, Hitoshi
    2017 IEEE 41ST ANNUAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE (COMPSAC), VOL 2, 2017, : 572 - 577
  • [46] A Survey of Defense Mechanisms Against Distributed Denial of Service (DDoS) Flooding Attacks
    Zargar, Saman Taghavi
    Joshi, James
    Tipper, David
    IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2013, 15 (04): : 2046 - 2069
  • [47] Research on the detection and defense systems against DDoS attacks in ad hoc networks
    Jing, Huang
    Wen, Wushao
    INFORMATION SCIENCE AND MANAGEMENT ENGINEERING, VOLS 1-3, 2014, 46 : 1161 - 1167
  • [48] A Root-based Defense Mechanism Against RPL Blackhole Attacks in Internet of Things Networks
    Jiang, Jun
    Liu, Yuhong
    Dezfouli, Behnam
    2018 ASIA-PACIFIC SIGNAL AND INFORMATION PROCESSING ASSOCIATION ANNUAL SUMMIT AND CONFERENCE (APSIPA ASC), 2018, : 1194 - 1199
  • [49] Taxonomy of DoS and DDoS attacks and desirable defense mechanism in a Cloud computing environment
    Gupta, B. B.
    Badve, Omkar P.
    NEURAL COMPUTING & APPLICATIONS, 2017, 28 (12): : 3655 - 3682
  • [50] Taxonomy of DoS and DDoS attacks and desirable defense mechanism in a Cloud computing environment
    B. B. Gupta
    Omkar P. Badve
    Neural Computing and Applications, 2017, 28 : 3655 - 3682