DocumentCode :
2778276
Title :
Filtering spoofed traffic at source end for defending against DoS / DDoS attacks
Author :
Malliga, S. ; Tamilarasi, A. ; Janani, M.
Author_Institution :
Dept. of Comput. Sci. & Eng., Kongu Eng. Coll., Thoppupalayam, Erode
fYear :
2008
fDate :
18-20 Dec. 2008
Firstpage :
1
Lastpage :
5
Abstract :
Tackling the challenge of distinguishing legitimate traffic from attack would aid in the detection of denial of service (DoS) / distributed DoS (DDoS) attacks. Spoofing of source address would further harden the detection of such attacks. In this paper, we propose a flow based scheme to detect the DoS attacks that adapts itself to the changes trends of the current traffic. The proposed system weeds out most of the spurious traffic at the source end, thus avoiding clogging of the target and the network. The proposed scheme distinguishes itself from other source end defenses, which use statistics to gather profiles. Information entropy, a measure to find correlation among traffic flows, is then used. Information entropy is used to deduce the current state of the dynamic network. Since the volume of the traffic at the source end would be moderate, it would be difficult to find the suspicious traffic at the source end. We found that the parameters we considered were good in identifying such traffic. We experimented our scheme using network simulator with network traffic traces and found the results were promising and presented them.
Keywords :
distributed processing; security of data; telecommunication traffic; DDoS; DoS; denial of service attacks; distributed denial of service attacks; information entropy; network traffic traces; spoofed traffic filter; traffic profiling; Computer crime; Computer science; Educational institutions; Filtering; Floods; Information entropy; Internet; Statistics; Telecommunication traffic; Traffic control; DDoS; DoS; Information entropy; Spoofing; Traffic profiling;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computing, Communication and Networking, 2008. ICCCn 2008. International Conference on
Conference_Location :
St. Thomas, VI
Print_ISBN :
978-1-4244-3594-4
Electronic_ISBN :
978-1-4244-3595-1
Type :
conf
DOI :
10.1109/ICCCNET.2008.4787695
Filename :
4787695
Link To Document :
بازگشت