• DocumentCode
    3352686
  • Title

    A source identification scheme against DDoS attacks in cluster interconnects

  • Author

    Manhee Lee ; Eun Jung Kim ; Cheol Won Lee

  • Author_Institution
    Texas A&M University
  • fYear
    2004
  • fDate
    18-18 Aug. 2004
  • Firstpage
    354
  • Lastpage
    361
  • Abstract
    Designing secure clusters has recently become a critical issue to make these systems robust to attacks from the Internet. The Distributed Denial of Service (DDoS) attack is one of the most serious problems in the current Internet. To defend against DDoS attacks, clusters usually depend on firewalls or Intrusion Detection Systems (IDS). However, once firewall and IDS are breached, the impact of DDoS attack within a cluster can be severe. That is because one infected system or one malicious user, which is believed to be trustworthy, may instantly paralyze the whole cluster through the high speed network. In this paper, we present a deterministic distance packet marking (DDPM) scheme to identify the source nodes generating spoofed IP packets in cluster interconnects. The scheme can be applied to many cluster interconnects such as mesh, torus and hypercube, which are popular in many commercial systems. Our scheme is practically attractive since it is scalable to large networks and does not incur much processing overhead on both switches and nodes.
  • Keywords
    Communication system security; Computer crime; Computer science; Computer security; Computer worms; Data security; High-speed networks; Intrusion detection; Robustness; Telecommunication traffic;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Parallel Processing Workshops, 2004. ICPP 2004 Workshops. Proceedings. 2004 International Conference on
  • Conference_Location
    Montreal, QC, Canada
  • ISSN
    1530-2016
  • Print_ISBN
    0-7695-2198-3
  • Type

    conf

  • DOI
    10.1109/ICPPW.2004.1328039
  • Filename
    1328039