DocumentCode
423248
Title
Secure collective defense system
Author
Chow, C. Edward ; Cai, Yu ; Wilkinson, David ; Godavari, Ganesh
Author_Institution
Dept. of Comput. Sci., Colorado Univ., Colorado Springs, CO, USA
Volume
4
fYear
2004
fDate
29 Nov.-3 Dec. 2004
Firstpage
2245
Abstract
In this paper, we present the design and implementation of the secure collective defense (SCOLD) system against distributed denial of service (DDoS) attacks. The key idea of SCOLD is to follow the intrusion tolerance paradigm and provide alternate routes via a set of proxy servers and alternate gateways when the normal route is unavailable or unstable due to network failures, congestion, or DDoS attacks. The BIND9 DNS server and its DNS update utilities are enhanced to support new DNS entries with indirect routing information. Protocol software for supporting the establishment of indirect routes based on the new DNS entries is developed for Linux systems. Experimental results show that SCOLD can improve the network security, availability and performance. Preliminary simulation results using NS2 indicate that the performance is scalable with respect to the indirect route initial setup overhead and processing overhead.
Keywords
Internet; Linux; computer network management; computer network reliability; network servers; routing protocols; security of data; telecommunication security; BIND9 DNS server; DDoS attacks; DNS update utilities; Internet; Linux systems; NS2; SCOLD system; alternate gateways; alternate routes; distributed denial of service; indirect routes; initial setup overhead; intrusion tolerance; network availability; network performance; network security; processing overhead; protocol software; proxy servers; secure collective defense system; Computer crime; Computer science; IP networks; Internet; Network servers; Protocols; Routing; Springs; Telecommunication traffic; Web server;
fLanguage
English
Publisher
ieee
Conference_Titel
Global Telecommunications Conference, 2004. GLOBECOM '04. IEEE
Print_ISBN
0-7803-8794-5
Type
conf
DOI
10.1109/GLOCOM.2004.1378408
Filename
1378408
Link To Document