DocumentCode :
1680895
Title :
MF (minority first) scheme for defeating distributed denial of service attacks
Author :
Ahn, Gaeil ; Kim, Kiyoung ; Jang, Jongsoo
Author_Institution :
Electron. & Telecommun. Res. Inst., Taejeon, South Korea
fYear :
2003
Firstpage :
1233
Abstract :
The one of the biggest barrier that hinders Internet development is security problem caused by malicious user. In this paper, we deal with distributed denial of service (DDoS) attacks that monopolize network resource, thus result in network or system congestion. Under DDoS attack, its very difficult to provide legitimate users with their fair share of available network resource. This paper proposes MF (minority first) as a traffic metering and control scheme that can provide quick weakness of DDoS attack, while protecting legitimate user´s traffic. The key idea of MF scheme is to provide good quality of service (QoS) to sources that use the network resource properly and poor QoS to sources that use network resource so excessively as to result in network congestion. MF scheme is composed of both source-traffic-trunk based metering and queue mapping mechanism for controlling malicious DDoS traffic and legitimate traffic. To show our scheme´s excellence, its performance is measured and compared with that of the existing queuing services and static rate-limit through simulation.
Keywords :
quality of service; queueing theory; telecommunication congestion control; telecommunication security; telecommunication traffic; Internet development; QoS; control scheme; distributed denial of service; legitimate traffic control; malicious distributed denial of service traffic control; minority first; network congestion; network resource; quality of service; queue mapping mechanism; security problem; source-traffic-trunk based metering; traffic metering; Communication system traffic control; Computational modeling; Computer crime; Computer hacking; Information security; Internet; Protection; Quality of service; Telecommunication congestion control; Traffic control;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computers and Communication, 2003. (ISCC 2003). Proceedings. Eighth IEEE International Symposium on
ISSN :
1530-1346
Print_ISBN :
0-7695-1961-X
Type :
conf
DOI :
10.1109/ISCC.2003.1214283
Filename :
1214283
Link To Document :
بازگشت