Title :
Shared Based Rate Limiting: An ISP level Solution to Deal DDoS Attacks
Author :
Sharma, Rajesh ; Kumar, Krishan ; Singh, Kuldip ; Joshi, R.C.
Author_Institution :
E&C Dept., I.I.T., Roorkee
Abstract :
Today distributed denial of service (DDoS) attacks is a major problem to the availability of Internet services. Several schemes have been proposed for countering DDoS attacks directed at an Internet server, but they suffer from a range of problems, some of them being impractical and others not being effective against these attacks. In this paper we propose a dynamic rate throttling technique that will greatly minimize the impact of attack. The basic mechanism is to have monitoring, rate limiting and filtering routers at various levels of ISPs. The participating routers, start there function after getting a signal from a server under attack. Our scheme is invoked only during attack times, and is able to mitigate attack traffic through dynamic filtering. Server tells edge routers to rate limit the traffic according to the share of traffic which is being passed through particular routers. The solution proposed is an ISP level solution which is practical enough to be implemented. We simulate the scheme in NS-2 in Linux system. We use an Internet type topology to test our scheme and web traffic was generated to evaluate the effectiveness of scheme. Our scheme shows good improvement over static router throttling techniques which were proposed earlier. Hence we believe that the scheme proposed in this paper seems to be a promising approach to prevent DDoS attacks
Keywords :
Internet; network servers; security of data; telecommunication congestion control; telecommunication network routing; telecommunication security; telecommunication traffic; DDoS; ISP level solution; Internet server; Internet service; Linux system; attack traffic mitigation; distributed denial of service attack; dynamic filtering; filtering router; throttling technique; Availability; Computer crime; Information filtering; Information filters; Linux; Monitoring; Topology; Traffic control; Web and internet services; Web server; Congestion control; Distributed Denial of service; Network level security and protection; router throttling;
Conference_Titel :
India Conference, 2006 Annual IEEE
Conference_Location :
New Delhi
Print_ISBN :
1-4244-0369-3
Electronic_ISBN :
1-4244-0370-7
DOI :
10.1109/INDCON.2006.302831