• DocumentCode
    2278370
  • Title

    Deployable overlay network for defense against distributed SYN flood attacks

  • Author

    Ohsita, Yuichi ; Ata, Shingo ; Murata, Masayuki

  • Author_Institution
    Graduate Sch. of Inf. Sci. & Technol., Osaka Univ., Japan
  • fYear
    2005
  • fDate
    17-19 Oct. 2005
  • Firstpage
    407
  • Lastpage
    412
  • Abstract
    Distributed denial-of-service attacks on public servers have recently become more serious. To assure that network services will not be interrupted, we need faster and more accurate defense mechanisms against malicious traffic, especially SYN floods. But single point defense (ex. firewalls) lacks a scalability to catch up the increase of the attack traffic. In this paper, we introduce a distributed defense mechanism using overlay networks. This mechanism detects attacks near the victim servers and alert messages are sent via the overlay networks. Then defense nodes identify legitimate traffic and block malicious ones. The legitimate traffic is protected via the overlay networks. We simulate and verify our proposed method can effectively block malicious traffic and protect legitimate traffic. We also describe the deployment scenario of our defense mechanism.
  • Keywords
    Internet; authorisation; network servers; telecommunication security; telecommunication traffic; transport protocols; TCP proxy; defense mechanism; denial-of-service attack; distributed SYN flood attack; distributed legitimate traffic protection; overlay network deployment; public server; Computer crime; Electronic mail; Floods; IP networks; Information science; Network servers; Protection; Scalability; Telecommunication traffic; Traffic control;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Communications and Networks, 2005. ICCCN 2005. Proceedings. 14th International Conference on
  • ISSN
    1095-2055
  • Print_ISBN
    0-7803-9428-3
  • Type

    conf

  • DOI
    10.1109/ICCCN.2005.1523897
  • Filename
    1523897