Unified defense against DDoS attacks

被引:0
|
作者
Muthuprasanna, M. [1 ]
Manimaran, C. [1 ]
Wang, Z. [1 ]
机构
[1] Iowa State Univ, Ames, IA 50011 USA
关键词
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
With DoS/DDoS attacks emerging as one of the primary security threats in today's Internet, the search is on for an efficient DDoS defense mechanism that would provide attack prevention, mitigation and traceback features, in as few packets as possible and with no collateral damage. Although several techniques have been proposed to tackle this growing menace, there exists no effective solution to date, due to the growing sophistication of the attacks and also the increasingly complex Internet architecture. In this paper, we propose an unified framework that integrates traceback and mitigation capabilities for an effective attack defense. Some significant aspects of our approach include: (1) a novel data cube model to represent the traceback information, and its slicing along the lines of path signatures rather than router signatures, (2) characterizing traceback as a transmission scheduling problem on the data cube representation, and achieving scheduling optimality using a novel metric called utility, (3) and finally an information delivery architecture employing both packet marking and data logging in a distributed manner to achieve faster response times. The proposed scheme can thus provide both per-packet mitigation and multi-packet traceback capabilities due to effective data slicing of the cube, and can attain higher detection speeds due to novel utility rate analysis. We also contrast this unified scheme with other well-known schemes in literature to understand the performance tradeoffs, while providing an experimental evaluation of the proposed scheme on real data sets.
引用
收藏
页码:1047 / +
页数:3
相关论文
共 50 条
  • [1] Smart Home Defense Against DDoS Attacks
    Huraj, Ladislav
    Simon, Marek
    Lietava, Jakub
    DATA SCIENCE AND ALGORITHMS IN SYSTEMS, 2022, VOL 2, 2023, 597 : 334 - 345
  • [2] A Responsive Defense Mechanism Against DDoS Attacks
    Mosharraf, Negar
    Jayasumana, Anura P.
    Ray, Indrakshi
    FOUNDATIONS AND PRACTICE OF SECURITY (FPS 2014), 2015, 8930 : 347 - 355
  • [3] Detection and Defense Mechanisms Against DDoS Attacks: A Review
    Pimpalkar, Archana S.
    Patil, A. R. Bhagat
    2015 INTERNATIONAL CONFERENCE ON INNOVATIONS IN INFORMATION, EMBEDDED AND COMMUNICATION SYSTEMS (ICIIECS), 2015,
  • [4] Defense Mechanisms Against DDoS Attacks in SDN Environment
    Kalkan, Kubra
    Gur, Gurkan
    Alagoz, Fatih
    IEEE COMMUNICATIONS MAGAZINE, 2017, 55 (09) : 175 - 179
  • [5] A Comprehensive Survey of Distributed Defense Techniques against DDoS Attacks
    Sachdeva, Monika
    Singh, Gurvinder
    Kumar, Krishan
    Singh, Kuldip
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2009, 9 (12): : 7 - 15
  • [6] MSOM: Efficient Mechanism for Defense against DDoS Attacks in VANET
    Al-Mehdhara, Mohammed
    Ruan, Na
    WIRELESS COMMUNICATIONS & MOBILE COMPUTING, 2021, 2021
  • [7] Global Orchestration of Cooperative Defense against DDoS Attacks for MEC
    Tan, Xinrui
    Li, Hongjia
    Wang, Liming
    Xu, Zhen
    2019 IEEE WIRELESS COMMUNICATIONS AND NETWORKING CONFERENCE (WCNC), 2019,
  • [8] Distributed and Predictive-Preventive Defense Against DDoS Attacks
    Jog, Manjiri
    Natu, Maitreya
    Shelke, Sushama
    PROCEEDINGS OF THE 16TH INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING AND NETWORKING, 2015,
  • [9] METHODOLOGIES FOR EVALUATING GAME THEORETIC DEFENSE AGAINST DDOS ATTACKS
    Khirwadkar, Tanmay
    Nguyen, Kien C.
    Nicol, David M.
    Basar, Tamer
    PROCEEDINGS OF THE 2010 WINTER SIMULATION CONFERENCE, 2010, : 697 - 707
  • [10] gore:: Routing-assisted defense against DDoS attacks
    Chou, ST
    Stavrou, A
    Ioannidis, J
    Keromytis, AD
    INFORMATION SECURITY, PROCEEDINGS, 2005, 3650 : 179 - 193