DocumentCode
3334195
Title
Defense against Bandwidth Attacks with Traffic Resource Management
Author
Luo, Hongli ; Shyu, Mei-Ling
Author_Institution
Indiana Purdue Univ., Fort Wayne
fYear
2007
fDate
13-15 Aug. 2007
Firstpage
190
Lastpage
195
Abstract
In this paper, a framework is proposed to defend against Internet bandwidth attacks with traffic resource management to provide service for legitimate users. Denial of service (DoS) is one of the major bandwidth attacks in the Internet. A DoS attack generates a large volume of traffic to consume the network bandwidth and degrade the service that legitimate users can obtain. Incoming traffic to the server is monitored and features are extracted for each connection. Anomaly detection technique is used to detect the abnormal traffic. Based on the outcome of the anomaly detection technique, the proposed resource management approach allocates suitable bandwidth. With the early detection of DoS, the attack traffic can be isolated. The bandwidth occupied by the attack can be reduced and protected for the legitimate users. Performances are compared under different attack loads with and without resource management. Simulation results show that bandwidth can be greatly saved from an attack and the service for the legitimate users can be protected during an attack.
Keywords
Internet; computer network management; telecommunication security; telecommunication traffic; Internet bandwidth attacks; anomaly detection technique; denial of service; legitimate users; traffic resource management; Bandwidth; Computer crime; Degradation; Monitoring; Network servers; Protection; Resource management; Telecommunication traffic; Web and internet services; Web server;
fLanguage
English
Publisher
ieee
Conference_Titel
Information Reuse and Integration, 2007. IRI 2007. IEEE International Conference on
Conference_Location
Las Vegas, IL
Print_ISBN
1-4244-1500-4
Electronic_ISBN
1-4244-1500-4
Type
conf
DOI
10.1109/IRI.2007.4296619
Filename
4296619
Link To Document