• DocumentCode
    3366527
  • Title

    Detection and Honeypot Based Redirection to Counter DDoS Attacks in ISP Domain

  • Author

    Sardana, Anjali ; Kumar, Krishan ; Joshi, R.C.

  • Author_Institution
    Indian Inst. of Technol., Roorkee
  • fYear
    2007
  • fDate
    29-31 Aug. 2007
  • Firstpage
    191
  • Lastpage
    196
  • Abstract
    The inherent vulnerabilities in TCT/IP architecture give dearth of opportunities to DDoS attackers. The array of schemes proposed for detection of these attacks in real time is either targeted towards low rate attacks or high bandwidth attacks. Tresence of low rate attacks leads to graceful degradation of QoS in the network thus making them further undetectable. In this paper, we propose a scheme that uses three lines of defense. The first line of defense is towards detecting the presence of low rate as well as high bandwidth attacks based on entropy variations in small time windows. The second line of defense identifies and tags attack flows in real time. The last line of defense is redirecting the attack flows to honeypot server that responds in contained manner to the attack flows, thus providing deterrence and maintaining QoS at ISP level. We validate the effectiveness of the approach with simulation in ns-2 on a Linux platform.
  • Keywords
    Internet; quality of service; security of data; DDoS attacks detection; ISP domain; TCT/IP architecture; entropy variations; high bandwidth attacks; honeypot based redirection; Bandwidth; Communication channels; Computer crime; Counting circuits; Degradation; Entropy; Information security; Linux; Service oriented architecture; TCPIP;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Assurance and Security, 2007. IAS 2007. Third International Symposium on
  • Conference_Location
    Manchester
  • Print_ISBN
    0-7695-2876-7
  • Electronic_ISBN
    978-0-7695-2876-2
  • Type

    conf

  • DOI
    10.1109/IAS.2007.23
  • Filename
    4299773