DocumentCode
2778276
Title
Filtering spoofed traffic at source end for defending against DoS / DDoS attacks
Author
Malliga, S. ; Tamilarasi, A. ; Janani, M.
Author_Institution
Dept. of Comput. Sci. & Eng., Kongu Eng. Coll., Thoppupalayam, Erode
fYear
2008
fDate
18-20 Dec. 2008
Firstpage
1
Lastpage
5
Abstract
Tackling the challenge of distinguishing legitimate traffic from attack would aid in the detection of denial of service (DoS) / distributed DoS (DDoS) attacks. Spoofing of source address would further harden the detection of such attacks. In this paper, we propose a flow based scheme to detect the DoS attacks that adapts itself to the changes trends of the current traffic. The proposed system weeds out most of the spurious traffic at the source end, thus avoiding clogging of the target and the network. The proposed scheme distinguishes itself from other source end defenses, which use statistics to gather profiles. Information entropy, a measure to find correlation among traffic flows, is then used. Information entropy is used to deduce the current state of the dynamic network. Since the volume of the traffic at the source end would be moderate, it would be difficult to find the suspicious traffic at the source end. We found that the parameters we considered were good in identifying such traffic. We experimented our scheme using network simulator with network traffic traces and found the results were promising and presented them.
Keywords
distributed processing; security of data; telecommunication traffic; DDoS; DoS; denial of service attacks; distributed denial of service attacks; information entropy; network traffic traces; spoofed traffic filter; traffic profiling; Computer crime; Computer science; Educational institutions; Filtering; Floods; Information entropy; Internet; Statistics; Telecommunication traffic; Traffic control; DDoS; DoS; Information entropy; Spoofing; Traffic profiling;
fLanguage
English
Publisher
ieee
Conference_Titel
Computing, Communication and Networking, 2008. ICCCn 2008. International Conference on
Conference_Location
St. Thomas, VI
Print_ISBN
978-1-4244-3594-4
Electronic_ISBN
978-1-4244-3595-1
Type
conf
DOI
10.1109/ICCCNET.2008.4787695
Filename
4787695
Link To Document