Source-based filtering scheme against DDOS attacks


Autoria(s): Yi, Fasheng; Yu, Shui; Zhou, Wanlei; Hai, Jing; Bonti, Alessio
Data(s)

01/01/2008

Resumo

IP address spoofing is employed by a lot of DDoS attack tools. Most of the current research on DDoS attack packet filtering depends on cooperation among routers, which is hard to achieve in real campaigns. Therefore, in the paper, we propose a novel filtering scheme based on source information in this paper to defend against various source IP address spoofing. The proposed method works independently at the potential victim side, and accumulates the source information of its clients, for instance, source IP addresses, hops from the server during attacks free period. When a DDoS attack alarm is raised, we can filter out the attack packets based on the accumulated knowledge of the legitimate clients. We divide the source IP addresses into <i>n</i>(1 ≤ <i>n</i> ≤ 32) segments in our proposed algorithm; as a result, we can therefore release the challenge storage and speed up the procedure of information retrieval. The system which is proposed by us and the experiments indicated that the proposed method works effectively and efficiently.<br />

Identificador

http://hdl.handle.net/10536/DRO/DU:30017709

Idioma(s)

eng

Publicador

Science & Engineering Research Support Centre, (SERSC)

Relação

http://dro.deakin.edu.au/eserv/DU:30017709/yi-sourcebased-2008.pdf

http://www.sersc.org/journals/IJDTA/vol1_no1/papers/02.pdf

Direitos

2008, SERSC

Palavras-Chave #Network Security #DDoS #Packet Filtering
Tipo

Journal Article