• DocumentCode
    3720572
  • Title

    Fast target link flooding attack detection scheme by analyzing traceroute packets flow

  • Author

    Takayuki Hirayama;Kentaroh Toyoda;Iwao Sasase

  • Author_Institution
    Dept. of Information and Computer Science, Keio University, 3-14-1 Hiyoshi, Kohoku, Yokohama, Kanagawa, 223-8522 Japan
  • fYear
    2015
  • Firstpage
    1
  • Lastpage
    6
  • Abstract
    Recently, a botnet based DDoS (Distributed Denial of Service) attack, called target link flooding attack, has been reported that cuts off specific links over the Internet and disconnects a specific region from other regions. Detecting or mitigating the target link flooding attack is more difficult than legacy DDoS attack techniques, since attacking flows do not reach the target region. Although many mitigation schemes are proposed, they detect the attack after it occurs. In this paper, we propose a fast target link flooding attack detection scheme by leveraging the fact that the traceroute packets are increased before the attack caused by the attacker´s reconnaissance. Moreover, by analyzing the characteristic of the target link flooding attack that the number of traceroute packets simultaneously increases in various regions over the network, we propose a detection scheme with multiple detection servers to eliminate false alarms caused by sudden increase of traceroute packets sent by legitimate users. We show the effectiveness of our scheme by computer simulations.
  • Keywords
    "Computational modeling","Reconnaissance"
  • Publisher
    ieee
  • Conference_Titel
    Information Forensics and Security (WIFS), 2015 IEEE International Workshop on
  • Type

    conf

  • DOI
    10.1109/WIFS.2015.7368594
  • Filename
    7368594