• DocumentCode
    423248
  • Title

    Secure collective defense system

  • Author

    Chow, C. Edward ; Cai, Yu ; Wilkinson, David ; Godavari, Ganesh

  • Author_Institution
    Dept. of Comput. Sci., Colorado Univ., Colorado Springs, CO, USA
  • Volume
    4
  • fYear
    2004
  • fDate
    29 Nov.-3 Dec. 2004
  • Firstpage
    2245
  • Abstract
    In this paper, we present the design and implementation of the secure collective defense (SCOLD) system against distributed denial of service (DDoS) attacks. The key idea of SCOLD is to follow the intrusion tolerance paradigm and provide alternate routes via a set of proxy servers and alternate gateways when the normal route is unavailable or unstable due to network failures, congestion, or DDoS attacks. The BIND9 DNS server and its DNS update utilities are enhanced to support new DNS entries with indirect routing information. Protocol software for supporting the establishment of indirect routes based on the new DNS entries is developed for Linux systems. Experimental results show that SCOLD can improve the network security, availability and performance. Preliminary simulation results using NS2 indicate that the performance is scalable with respect to the indirect route initial setup overhead and processing overhead.
  • Keywords
    Internet; Linux; computer network management; computer network reliability; network servers; routing protocols; security of data; telecommunication security; BIND9 DNS server; DDoS attacks; DNS update utilities; Internet; Linux systems; NS2; SCOLD system; alternate gateways; alternate routes; distributed denial of service; indirect routes; initial setup overhead; intrusion tolerance; network availability; network performance; network security; processing overhead; protocol software; proxy servers; secure collective defense system; Computer crime; Computer science; IP networks; Internet; Network servers; Protocols; Routing; Springs; Telecommunication traffic; Web server;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Global Telecommunications Conference, 2004. GLOBECOM '04. IEEE
  • Print_ISBN
    0-7803-8794-5
  • Type

    conf

  • DOI
    10.1109/GLOCOM.2004.1378408
  • Filename
    1378408