DocumentCode
2408268
Title
Mitigating DoS attack through selective bin verification
Author
Sherr, Micah ; Greenwald, Michael ; Gunter, Carl A. ; Khanna, Sanjeev ; Venkatesh, Santosh S.
Author_Institution
Sch. of Eng. & Appl. Sci., Pennsylvania Univ., Philadelphia, PA, USA
fYear
2005
fDate
6 Nov. 2005
Firstpage
7
Lastpage
12
Abstract
Despite considerable attention from both the academic and commercial communities, denial-of-service (DoS) attacks represent a growing threat to network administrators and service providers. A large number of proposed DoS countermeasures attempt to detect an attack in-progress and filter out the DoS attack packets. These techniques often depend on the instantiation of sophisticated routing mechanisms and the ability to differentiate between normal and malicious messages. Unfortunately, neither of these prerequisites may be practical or possible. We propose and evaluate a defense against DoS attacks which we call selective bin verification. The technique shows promise against large DoS attacks, even when attack packets are able to permeate the network and reach the target of their attack. We explore the effectiveness of our technique by implementing an experimental testbed in which selective bin verification is successfully used to protect against DoS attacks. We formally describe the mathematical properties of our approach and delineate "tuning" parameters for defending against various attacks.
Keywords
telecommunication network routing; telecommunication security; DoS attack mitigation; denial-of-service attacks; routing mechanisms; selective bin verification; Computer crime; Computer science; Filters; Humans; Intrusion detection; Protection; Protocols; Routing; Telecommunication traffic; Testing;
fLanguage
English
Publisher
ieee
Conference_Titel
Secure Network Protocols, 2005. (NPSec). 1st IEEE ICNP Workshop on
Print_ISBN
0-7803-9427-5
Type
conf
DOI
10.1109/NPSEC.2005.1532046
Filename
1532046
Link To Document