Unified defense against DDoS attacks

被引:0
|
作者
Muthuprasanna, M. [1 ]
Manimaran, C. [1 ]
Wang, Z. [1 ]
机构
[1] Iowa State Univ, Ames, IA 50011 USA
关键词
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
With DoS/DDoS attacks emerging as one of the primary security threats in today's Internet, the search is on for an efficient DDoS defense mechanism that would provide attack prevention, mitigation and traceback features, in as few packets as possible and with no collateral damage. Although several techniques have been proposed to tackle this growing menace, there exists no effective solution to date, due to the growing sophistication of the attacks and also the increasingly complex Internet architecture. In this paper, we propose an unified framework that integrates traceback and mitigation capabilities for an effective attack defense. Some significant aspects of our approach include: (1) a novel data cube model to represent the traceback information, and its slicing along the lines of path signatures rather than router signatures, (2) characterizing traceback as a transmission scheduling problem on the data cube representation, and achieving scheduling optimality using a novel metric called utility, (3) and finally an information delivery architecture employing both packet marking and data logging in a distributed manner to achieve faster response times. The proposed scheme can thus provide both per-packet mitigation and multi-packet traceback capabilities due to effective data slicing of the cube, and can attain higher detection speeds due to novel utility rate analysis. We also contrast this unified scheme with other well-known schemes in literature to understand the performance tradeoffs, while providing an experimental evaluation of the proposed scheme on real data sets.
引用
收藏
页码:1047 / +
页数:3
相关论文
共 50 条
  • [21] Defense mechanism using overlay against DDoS attacks on converged networks
    Kim, Mihui
    Doh, Inshil
    Chae, Kijoon
    9TH INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION TECHNOLOGY: TOWARD NETWORK INNOVATION BEYOND EVOLUTION, VOLS 1-3, 2007, : 1539 - +
  • [22] Simulation of Internet DDoS attacks and defense
    Kotenko, Igor
    Ulanov, Alexander
    INFORMATION SECURITY, PROCEEDINGS, 2006, 4176 : 327 - 342
  • [23] DDOS attacks and defense mechanisms: A classification
    Douligeris, C
    Mitrokotsa, A
    PROCEEDINGS OF THE 3RD IEEE INTERNATIONAL SYMPOSIUM ON SIGNAL PROCESSING AND INFORMATION TECHNOLOGY, 2003, : 190 - 193
  • [24] A defense system against DDoS attacks by large-scale IP traceback
    Xiang, Y
    Zhou, WL
    THIRD INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY AND APPLICATIONS, VOL 2, PROCEEDINGS, 2005, : 431 - 436
  • [25] Neighbor Stranger Discrimination: A New Defense Mechanism Against Internet DDoS Attacks
    Itani, Sleiman
    Aaraj, Najwa
    Abdelahad, Darine
    Kayssi, Ayman
    3RD ACS/IEEE INTERNATIONAL CONFERENCE ON COMPUTER SYSTEMS AND APPLICATIONS, 2005, 2005,
  • [26] A Distributed Collaborative Entrance Defense Framework Against DDoS Attacks on Satellite Internet
    Guo, Wei
    Xu, Jin
    Pei, Yukui
    Yin, Liuguo
    Jiang, Chunxiao
    Ge, Ning
    IEEE INTERNET OF THINGS JOURNAL, 2022, 9 (17) : 15497 - 15510
  • [27] Joint application and network defense against DDoS flooding attacks in the future Internet
    Karrer, Roger P.
    Kuehn, Ulrich
    Huehn, Thomas
    FGCN: PROCEEDINGS OF THE 2008 SECOND INTERNATIONAL CONFERENCE ON FUTURE GENERATION COMMUNICATION AND NETWORKING, VOLS 1 AND 2, 2008, : 9 - +
  • [28] Dolus: Cyber Defense using Pretense against DDoS Attacks in Cloud Platforms
    Neupane, Roshan Lal
    Neely, Travis
    Chettri, Nishant
    Vassell, Mark
    Zhang, Yuanxun
    Calyam, Prasad
    ICDCN'18: PROCEEDINGS OF THE 19TH INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING AND NETWORKING, 2018,
  • [29] Implementation of an SDN-based Security Defense Mechanism Against DDoS Attacks
    Lin, Hsiao-Chung
    Wang, Ping
    JOINT 2016 INTERNATIONAL CONFERENCE ON ECONOMICS AND MANAGEMENT ENGINEERING (ICEME 2016) AND INTERNATIONAL CONFERENCE ON ECONOMICS AND BUSINESS MANAGEMENT (EBM 2016), 2016, : 377 - 383
  • [30] A Hybrid Intrusion Detection Architecture for Defense against DDoS Attacks in Cloud Environment
    Gupta, Sanchika
    Horrow, Susmita
    Sardana, Anjali
    CONTEMPORARY COMPUTING, 2012, 306 : 498 - 499