Defending against Distributed Denial-of-Service Attacks with Weight-Fair Router Throttles
نویسنده
چکیده
A high profile internet server is always a target of denial-of-service attacks. In this project, we propose a novel technique for protecting an internet server from distributed denial-of-service attacks. The defense mechanism is based on a distributed algorithm that performs weight-fair throttling at the upstream routers. The throttling is weight-fair because the traffics destined for the server are controlled (increased or decreased ) by the leaky-buckets at the routers based on the number of users connected, directly or through other routers, to each router. To the best of our knowledge, this is the first weightfair technique for saving an internet server from denial-of-service attacks. The system is guaranteed to work even if some of the routers are compromised. Furthermore, in the beginning of the algorithm, the server’s capacity is underestimated by the routers so as to protect the server from any sudden initial attack. Keywords-Network security; Distributed denial-of-service attack; Internet server;
منابع مشابه
Defending Against Distributed Denial-of-Service Attacks With Weight-Fair Router Throttling
A high profile internet server is always a target of denial-of-service attacks. In this paper, we propose a novel technique for protecting an internet server from distributed denial-of-service attacks. The defense mechanism is based on a distributed algorithm that performs weight-fair throttling at the upstream routers. The throttling is weight-fair because the traffics destined for the server ...
متن کاملProtection from distributed denial of service attacks using history-based IP filtering
In this paper, we introduce a practical scheme to defend against Distributed Denial of Service (DDoS) attacks based on IP source address filtering. The edge router keeps a history of all the legitimate IP addresses which have previously appeared in the network. When the edge router is overloaded, this history is used to decide whether to admit an incoming IP packet. Unlike other proposals to de...
متن کاملDefending Against Distributed Denial of Service Attacks Using Selective Pushback
In this paper, we introduce a router-based system to defend against Distributed Denial of Service (DDoS) attacks. DDoS attacks are treated as a congestioncontrol problem. The main issue is to identify the congestion and then pushback a packet filter to the router closest to the source that causes congestion. Unlike previous approaches, we propose an anomaly detection scheme using source informa...
متن کاملScheme of Defending Against DDoS Attacks in Large-Scale ISP Networks
A scheme that defending against distributed denial of service (DDoS) attacks adopts the mechanism of Distribution-based Secure Overlay Nodes (DSON) to a large-scale ISP (Internet Service Provider) network is presented. The scheme uses local BPG announcement to divert traffic to the overlay network when experiencing high load, then filtering algorithm based on the technology of signal processing...
متن کاملS a Arunmozhi and Y Venkataramani: Resilient Scheme against Reduction of Quality (roq) Distributed Denial of Service Attack in Manet
Defending against denial-of-service attacks (DoS) in a mobile ad hoc network (MANET) is challenging because of the dynamic network topology. Security primitives must be dynamically adjusted to cope with the network. The Reduction-of-Quality (RoQ) Distributed Denial of Service (DDoS) attack is one which throttles the tcp throughput heavily and reduces the quality-of-service (QoS) to end systems ...
متن کامل