• DocumentCode
    2209978
  • Title

    Available bandwidth estimation and its application in detection of DDoS attacks

  • Author

    He, Li ; Tang, Binhua ; Yu, Shunzheng

  • Author_Institution
    Dept. of Electron. & Commun. Eng., Sun Yat-Sen Univ., Guangzhou, China
  • fYear
    2008
  • fDate
    19-21 Nov. 2008
  • Firstpage
    1187
  • Lastpage
    1191
  • Abstract
    Detection of distributed denial of service (DDoS) attacks over the Internet is crucial for many Internet applications, such as electronic commerce, network games, P2P, etc. Based on anomaly detection information, network route selection, quality of service (QoS) provision, and traffic engineering can be performed to bypass the abnormal areas or to immigrate the attack traffic. To detect the DDoS attacks in networks outside manageable areas, we need to send probing packets. This paper first surveys the existing available bandwidth estimation tools (ABETs) and divides them into two categories. Most ABETs can measure the available bandwidth of a path over networks, and provide knowledge about the tight link of the path. This paper then presents a method using the ABETs and the bottleneck localization tools to estimate total available bandwidth inside a network from the network edge without additional cooperation of the edge or core routers. The method continuously measures the network bandwidth. The measurement results are then used to detect whether DDoS attacks appear by a special cumulative sum (CUSUM) algorithm. Simulations verified the efficiency of the network available bandwidth measurement method and the detection algorithm.
  • Keywords
    Internet; bandwidth allocation; quality of service; security of data; telecommunication network routing; telecommunication security; telecommunication traffic; DDoS attack detection; Internet; anomaly detection information; available bandwidth estimation tool; bottleneck localization tool; cumulative sum algorithm; distributed denial of service attack; network bandwidth estimation; network route selection; network traffic engineering; quality of service; Bandwidth; Biomedical engineering; Computer crime; Electronic commerce; IP networks; Load management; Quality of service; Sun; Telecommunication traffic; Web and internet services;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Communication Systems, 2008. ICCS 2008. 11th IEEE Singapore International Conference on
  • Conference_Location
    Guangzhou
  • Print_ISBN
    978-1-4244-2423-8
  • Electronic_ISBN
    978-1-4244-2424-5
  • Type

    conf

  • DOI
    10.1109/ICCS.2008.4737370
  • Filename
    4737370