• DocumentCode
    2778276
  • Title

    Filtering spoofed traffic at source end for defending against DoS / DDoS attacks

  • Author

    Malliga, S. ; Tamilarasi, A. ; Janani, M.

  • Author_Institution
    Dept. of Comput. Sci. & Eng., Kongu Eng. Coll., Thoppupalayam, Erode
  • fYear
    2008
  • fDate
    18-20 Dec. 2008
  • Firstpage
    1
  • Lastpage
    5
  • Abstract
    Tackling the challenge of distinguishing legitimate traffic from attack would aid in the detection of denial of service (DoS) / distributed DoS (DDoS) attacks. Spoofing of source address would further harden the detection of such attacks. In this paper, we propose a flow based scheme to detect the DoS attacks that adapts itself to the changes trends of the current traffic. The proposed system weeds out most of the spurious traffic at the source end, thus avoiding clogging of the target and the network. The proposed scheme distinguishes itself from other source end defenses, which use statistics to gather profiles. Information entropy, a measure to find correlation among traffic flows, is then used. Information entropy is used to deduce the current state of the dynamic network. Since the volume of the traffic at the source end would be moderate, it would be difficult to find the suspicious traffic at the source end. We found that the parameters we considered were good in identifying such traffic. We experimented our scheme using network simulator with network traffic traces and found the results were promising and presented them.
  • Keywords
    distributed processing; security of data; telecommunication traffic; DDoS; DoS; denial of service attacks; distributed denial of service attacks; information entropy; network traffic traces; spoofed traffic filter; traffic profiling; Computer crime; Computer science; Educational institutions; Filtering; Floods; Information entropy; Internet; Statistics; Telecommunication traffic; Traffic control; DDoS; DoS; Information entropy; Spoofing; Traffic profiling;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computing, Communication and Networking, 2008. ICCCn 2008. International Conference on
  • Conference_Location
    St. Thomas, VI
  • Print_ISBN
    978-1-4244-3594-4
  • Electronic_ISBN
    978-1-4244-3595-1
  • Type

    conf

  • DOI
    10.1109/ICCCNET.2008.4787695
  • Filename
    4787695