Title :
Countering denial-of-service attacks using congestion triggered packet sampling and filtering
Author :
Huang, Yih ; Pullen, J. Mark
Author_Institution :
Dept. of Comput. Sci., George Mason Univ., Fairfax, VA, USA
fDate :
6/23/1905 12:00:00 AM
Abstract :
Denial-of-service (DoS) attacks have received a great amount of attention in research communities and general public alike, due to recent, high-profile attacks against major Internet e-commerce sites. We present a countermeasure against such attacks, called the congestion-triggered packet sampling/packet filtering (CTPS/PF) architecture. With CTPS/PF, a packet sampling mechanism that is integrated with the congestion control mechanism at routers is used to detect DoS attacks, and packet filters are activated only when sampling results warrant action. One important concern in deploying any form of traffic analysis in the critical data-forwarding paths of the Internet is performance. Our sample processing algorithm takes into account the confidence indicators of statistic results to raise alarms with relatively small numbers of samples. Moreover, the per-sample processing complexity is only O(1). Our simulation study reveals that the CTPS/PF architecture is able to detect the presence of DoS attacks and take proper action within hundreds of milliseconds to tens of seconds. Moreover, the average sampling overhead during a congestion period is in the vicinity of 1 sample per second
Keywords :
Internet; sampling methods; security of data; telecommunication congestion control; telecommunication security; Internet e-commerce sites; congestion triggered packet filtering; congestion triggered packet sampling; data-forwarding paths; denial-of-service attacks; sampling overhead; traffic analysis; Computer crime; Computer science; Electronic mail; Information filtering; Information filters; Internet; Multiprotocol label switching; Performance analysis; Sampling methods; Traffic control;
Conference_Titel :
Computer Communications and Networks, 2001. Proceedings. Tenth International Conference on
Conference_Location :
Scottsdale, AZ
Print_ISBN :
0-7803-7128-3
DOI :
10.1109/ICCCN.2001.956309