DocumentCode :
1632064
Title :
Countering denial-of-service attacks using congestion triggered packet sampling and filtering
Author :
Huang, Yih ; Pullen, J. Mark
Author_Institution :
Dept. of Comput. Sci., George Mason Univ., Fairfax, VA, USA
fYear :
2001
fDate :
6/23/1905 12:00:00 AM
Firstpage :
490
Lastpage :
494
Abstract :
Denial-of-service (DoS) attacks have received a great amount of attention in research communities and general public alike, due to recent, high-profile attacks against major Internet e-commerce sites. We present a countermeasure against such attacks, called the congestion-triggered packet sampling/packet filtering (CTPS/PF) architecture. With CTPS/PF, a packet sampling mechanism that is integrated with the congestion control mechanism at routers is used to detect DoS attacks, and packet filters are activated only when sampling results warrant action. One important concern in deploying any form of traffic analysis in the critical data-forwarding paths of the Internet is performance. Our sample processing algorithm takes into account the confidence indicators of statistic results to raise alarms with relatively small numbers of samples. Moreover, the per-sample processing complexity is only O(1). Our simulation study reveals that the CTPS/PF architecture is able to detect the presence of DoS attacks and take proper action within hundreds of milliseconds to tens of seconds. Moreover, the average sampling overhead during a congestion period is in the vicinity of 1 sample per second
Keywords :
Internet; sampling methods; security of data; telecommunication congestion control; telecommunication security; Internet e-commerce sites; congestion triggered packet filtering; congestion triggered packet sampling; data-forwarding paths; denial-of-service attacks; sampling overhead; traffic analysis; Computer crime; Computer science; Electronic mail; Information filtering; Information filters; Internet; Multiprotocol label switching; Performance analysis; Sampling methods; Traffic control;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computer Communications and Networks, 2001. Proceedings. Tenth International Conference on
Conference_Location :
Scottsdale, AZ
ISSN :
1095-2055
Print_ISBN :
0-7803-7128-3
Type :
conf
DOI :
10.1109/ICCCN.2001.956309
Filename :
956309
Link To Document :
بازگشت