• DocumentCode
    415102
  • Title

    Transient performance of PacketScore for blocking DDoS attacks

  • Author

    Chuah, Mooi Choo ; Lau, Wing Cheong ; Kim, Yoohwan ; Chao, H. Jonathan

  • Author_Institution
    Dept. of CSE, Lehigh Univ., Bethlehem, PA, USA
  • Volume
    4
  • fYear
    2004
  • fDate
    20-24 June 2004
  • Firstpage
    1892
  • Abstract
    Distributed denial of service (DDoS) attack is a critical threat to the Internet. Recently we have proposed the PacketScore scheme, a DDoS defense architecture that supports automated attack detection, on-line attack characterization and attack blocking. Its key idea is to use a statistics-based packet scoring mechanism to distinguish between legitimate and non-legitimate packets and discard packets based on the packet scores. In order for such an approach to work, we need to perform on-line traffic characterizations, and compare such characterizations with the nominal profiles (generated from past history or off-line analysis). The threshold used for the score-based selective packet discard decision is dynamically adjusted based on the score distribution of recent incoming packets. In our previous paper [Kim et al. 2004], we discuss how our proposed system performs in different attack scenarios. In this paper, we first give a brief review of the PacketScore approach and further elaborate on the transient performance under varying attack types and intensities, which may be exploited in more sophisticated attacks. We then show that PacketScore is well capable of blocking such sophisticated attacks by simply adjusting the measurement window time scale to closely track the attack profile.
  • Keywords
    Internet; packet switching; statistical analysis; telecommunication security; telecommunication traffic; transient analysis; DDoS attack blocking; Internet; PacketScore scheme; automated attack detection; distributed denial of service; off-line analysis; online attack characterization; online traffic characterizations; transient performance; Chaotic communication; Computer crime; Computer security; Fasteners; Filters; IP networks; Pattern recognition; Protocols; Scalability; Telecommunication traffic;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Communications, 2004 IEEE International Conference on
  • Print_ISBN
    0-7803-8533-0
  • Type

    conf

  • DOI
    10.1109/ICC.2004.1312849
  • Filename
    1312849