Intelligent DDoS packet filtering in high-speed networks


Autoria(s): Xiang, Yang; Zhou, Wanlei
Data(s)

01/01/2005

Resumo

Currently high-speed networks have been attacked by successive waves of Distributed Denial of Service (DDoS) attacks. There are two major challenges on DDoS defense in the high-speed networks. One is to sensitively and accurately detect attack traffic, and the other is to filter out the attack traffic quickly, which mainly depends on high-speed packet classification. Unfortunately most current defense approaches can not efficiently detect and quickly filter out attack traffic. Our approach is to find the network anomalies by using neural network, deploy the system at distributed routers, identify the attack packets, and then filter them quickly by a Bloom filter-based classifier. The evaluation results show that this approach can be used to defend against both intensive and subtle DDoS attacks, and can catch DDoS attacks’ characteristic of starting from multiple sources to a single victim. The simple complexity, high classification speed and low storage requirements make it especially suitable for DDoS defense in high-speed networks. <br />

Identificador

http://hdl.handle.net/10536/DRO/DU:30003136

Idioma(s)

eng

Publicador

Springer-Verlag

Relação

http://dro.deakin.edu.au/eserv/DU:30003136/xiang-intelligentddos-2005.pdf

http://www.springerlink.com/content/yp84w58v434k85u8/fulltext.pdf

Direitos

2005, Springer-Verlag

Tipo

Journal Article