DocumentCode :
3388927
Title :
Heterogeneous tracers against DDoS attacks
Author :
Wang, Chun-Hsin ; Chang, Da Chun
Author_Institution :
Dept. of Comput. Sci. & Inf. Eng., Chung Hua Univ., Hsinchu, Taiwan
fYear :
2011
fDate :
25-28 Sept. 2011
Firstpage :
723
Lastpage :
727
Abstract :
To solve the DoS/DDoS problems efficiently, the first things is to locate the attack origins and then cooperate the filter(s) nearby for dropping abnormal packets in time. The original routers can´t provide these functions such as tracking, filtering, and etc. They have to be enhanced with additional functions to defend DoS/DDoS attacks. We refer the enhanced routers as tracers. According to the characteristic, cost and necessity of tracers, three kinds of heterogeneous tracers are selected, namely tunneling-enabled tracers, marking-enabled tracers and filtering-enabled tracers. The tunneling-enabled tracers with the lowest cost can alter the path of the passing packets to destination easily. In this paper, we study how to use tunneling-enabled tracers efficiently to forward packets to the best marking-enabled or filtering-enabled tracer for locating attack origins and filtering abnormal packets in time. Four methods are proposed and compared with the optimal solution. The fourth method with the assistance of marking-enabled tracers has the best performance of protecting network bandwidth by simulation result.
Keywords :
telecommunication network routing; telecommunication security; DDoS attacks; filtering- enabled tracers; heterogeneous tracers; network bandwidth; network security problems; routers; tunneling-enabled tracers; Barium; Tunneling; DDoS; Tracers;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Communication Technology (ICCT), 2011 IEEE 13th International Conference on
Conference_Location :
Jinan
Print_ISBN :
978-1-61284-306-3
Type :
conf
DOI :
10.1109/ICCT.2011.6157971
Filename :
6157971
Link To Document :
بازگشت