Unified defense against DDoS attacks

被引:0
|
作者
Muthuprasanna, M. [1 ]
Manimaran, C. [1 ]
Wang, Z. [1 ]
机构
[1] Iowa State Univ, Ames, IA 50011 USA
关键词
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
With DoS/DDoS attacks emerging as one of the primary security threats in today's Internet, the search is on for an efficient DDoS defense mechanism that would provide attack prevention, mitigation and traceback features, in as few packets as possible and with no collateral damage. Although several techniques have been proposed to tackle this growing menace, there exists no effective solution to date, due to the growing sophistication of the attacks and also the increasingly complex Internet architecture. In this paper, we propose an unified framework that integrates traceback and mitigation capabilities for an effective attack defense. Some significant aspects of our approach include: (1) a novel data cube model to represent the traceback information, and its slicing along the lines of path signatures rather than router signatures, (2) characterizing traceback as a transmission scheduling problem on the data cube representation, and achieving scheduling optimality using a novel metric called utility, (3) and finally an information delivery architecture employing both packet marking and data logging in a distributed manner to achieve faster response times. The proposed scheme can thus provide both per-packet mitigation and multi-packet traceback capabilities due to effective data slicing of the cube, and can attain higher detection speeds due to novel utility rate analysis. We also contrast this unified scheme with other well-known schemes in literature to understand the performance tradeoffs, while providing an experimental evaluation of the proposed scheme on real data sets.
引用
收藏
页码:1047 / +
页数:3
相关论文
共 50 条
  • [41] SIP Protector: Defense Architecture Mitigating DDoS Flood Attacks Against SIP servers
    Stanek, Jan
    Kencl, Lukas
    2012 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2012,
  • [42] DIDA: Distributed In-Network Defense Architecture Against Amplified Reflection DDoS Attacks
    Khooi, Xin Zhe
    Csikor, Levente
    Divakaran, Dinil Mon
    Kang, Min Suk
    PROCEEDINGS OF THE 2020 6TH IEEE CONFERENCE ON NETWORK SOFTWARIZATION (NETSOFT 2020): BRIDGING THE GAP BETWEEN AI AND NETWORK SOFTWARIZATION, 2020, : 277 - 281
  • [43] Collaborative Defense Method Against DDoS Attacks on SDN-Architected Cloud Servers
    Zhang, Yiying
    Xu, Yao
    Han, Longzhe
    Liang, Kun
    Li, Wenjing
    ADVANCED INTELLIGENT COMPUTING TECHNOLOGY AND APPLICATIONS, PT IV, ICIC 2024, 2024, 14865 : 362 - 370
  • [44] Securing IIoT systems against DDoS attacks with adaptive moving target defense strategies
    Swati
    Roy, Sangita
    Singh, Jawar
    Mathew, Jimson
    SCIENTIFIC REPORTS, 2025, 15 (01):
  • [45] Adversarial Deep Learning approach detection and defense against DDoS attacks in SDN environments
    Novaes, Matheus P.
    Carvalho, Luiz F.
    Lloret, Jaime
    Proenca, Mario Lemes, Jr.
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2021, 125 : 156 - 167
  • [46] Source-Based Defense Against DDoS Attacks in SDN Based on sFlow and SOM
    Wang, Meng
    Lu, Yiqin
    Qin, Jiancheng
    IEEE ACCESS, 2022, 10 : 2097 - 2116
  • [47] Autonomous Cyber Defense Against Dynamic Multi-strategy Infrastructural DDoS Attacks
    Dutta, Ashutosh
    Al-Shaer, Ehab
    Chatterjee, Samrat
    Duan, Qi
    2023 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY, CNS, 2023,
  • [48] Research on Multi-Layer Defense against DDoS Attacks in Intelligent Distribution Networks
    Xu, Kai
    Li, Zemin
    Liang, Nan
    Kong, Fanchun
    Lei, Shaobo
    Wang, Shengjie
    Paul, Agyemang
    Wu, Zhefu
    ELECTRONICS, 2024, 13 (18)
  • [49] Online Orchestration of Cooperative Defense against DDoS Attacks for 5G MEC
    Li, Hongjia
    Wang, Liming
    2018 IEEE WIRELESS COMMUNICATIONS AND NETWORKING CONFERENCE (WCNC), 2018,
  • [50] A Hybrid Lightweight Defense System Against Address Spoofing Based DDoS Attacks in SDN
    Sinha, Mitali
    Bera, Padmalochan
    Satpathy, Manoranjan
    Sahoo, Kshira Sagar
    SECURITY AND PRIVACY, 2025, 8 (02):