RCS: A distributed mechanism against link flooding DDoS attacks

被引:0
|
作者
Cui, Yong [1 ]
Song, Lingjian [1 ]
Xu, Ke [1 ]
机构
[1] Tsinghua Univ, Dept Comp Sci & Technol, Beijing 100084, Peoples R China
关键词
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
DoS/DDoS attacks especially the Link Flooding have exerted severe threat on Internet. In this paper we propose a novel mechanism called Rate Control System (RCS) against Link Flooding based on the correlation analysis of upper link flows. According to the feature of aggregate in DDoS attack, RCS takes DDoS attack problem as a way of flow control to simplify the situation and deploys the flow controller at the routers near the victims. As the key point of our mechanism, an algorithm is designed to differentiate the malicious packets and the normal ones and we classify the packets according to TCP flags in order to tell different flows apart. In addition we detect the malicious aggregate using correlation analysis to make clear the type and the location of the attack. Simulation results demonstrate the performance for detecting the Link Flooding DDoS attacks.
引用
收藏
页码:764 / +
页数:3
相关论文
共 50 条
  • [1] A Distributed Mechanism to Protect Against DDoS Attacks
    Mosharraf, Negar
    Jayasumana, Anura P.
    Ray, Indrakshi
    DATA AND APPLICATIONS SECURITY AND PRIVACY XXXI, DBSEC 2017, 2017, 10359 : 529 - 540
  • [2] A distributed filtering mechanism against DDoS attacks: ScoreForCore
    Kalkan, Kubra
    Alagoz, Fatih
    COMPUTER NETWORKS, 2016, 108 : 199 - 209
  • [3] A Survey of Defense Mechanisms Against Distributed Denial of Service (DDoS) Flooding Attacks
    Zargar, Saman Taghavi
    Joshi, James
    Tipper, David
    IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2013, 15 (04): : 2046 - 2069
  • [4] Defending Against Evolving DDoS Attacks: A Case Study Using Link Flooding Incidents
    Kang, Min Suk
    Gligor, Virgil D.
    Sekar, Vyas
    SECURITY PROTOCOLS XXIV, 2017, 10368 : 47 - 57
  • [5] Superpoint-Based Detection Against Distributed Denial of Service (DDoS) Flooding Attacks
    Jiang, Hong
    Chen, Shuqiao
    Hu, Hongchao
    Zhang, Mingming
    2015 IEEE 21ST INTERNATIONAL WORKSHOP ON LOCAL & METROPOLITAN AREA NETWORKS (LANMAN), 2015,
  • [6] Cooperative mechanism against DDoS attacks
    Zhang, GS
    Parashar, M
    SAM '05: PROCEEDINGS OF THE 2005 INTERNATIONAL CONFERENCE ON SECURITY AND MANAGEMENT, 2005, : 86 - 96
  • [7] A distributed defense framework for flooding-based DDoS attacks
    You, Yonghua
    Zulkernine, Mohammad
    Haque, Anwar
    ARES 2008: PROCEEDINGS OF THE THIRD INTERNATIONAL CONFERENCE ON AVAILABILITY, SECURITY AND RELIABILITY, 2008, : 245 - +
  • [8] Defending Against Evolving DDoS Attacks: A Case Study Using Link Flooding Incidents (Transcript of Discussion)
    Gligor, Virgil D.
    SECURITY PROTOCOLS XXIV, 2017, 10368 : 58 - 66
  • [9] Securing Cloud Servers against Flooding Based DDOS Attacks
    Chopade, S. S.
    Pandey, K. U.
    Bhade, D. S.
    2013 INTERNATIONAL CONFERENCE ON COMMUNICATION SYSTEMS AND NETWORK TECHNOLOGIES (CSNT 2013), 2013, : 524 - 528
  • [10] A Responsive Defense Mechanism Against DDoS Attacks
    Mosharraf, Negar
    Jayasumana, Anura P.
    Ray, Indrakshi
    FOUNDATIONS AND PRACTICE OF SECURITY (FPS 2014), 2015, 8930 : 347 - 355