DocumentCode
459447
Title
An Efficient Defense against Distributed Denial-of-Service Attacks using Congestion Path Marking
Author
Yoohwan Kim ; El Al, Ahmed Abd ; Jo, Ju-Yeon ; Yang, Mei ; Jiang, Yingtao
Author_Institution
School of Computer Science. Email: yoohwan@cs.unlv.edu
Volume
5
fYear
2006
fDate
38869
Firstpage
2159
Lastpage
2164
Abstract
The Distributed Denial-of-Service (DDoS) attack is a serious threat in the Internet, and an effective method is needed for distinguishing the attack traffic from the legitimate traffic. In DDoS attacks, the large volume of attack streams cause self-induced congestion or higher utilization of the links. Based on this observation, we propose the Congestion Path Marking (CPM) scheme to identify and drop the attack packets. In this proposed scheme, we store the link utilization information in the packet header so that suspicious attack packets can be distinguished. Each router along the path records its local congestion information, and this information is accumulated to represent the overall congestion level that a packet has experienced. To enable light-weight real-time processing, we employ a RED-like random packet dropping mechanism at the victim´s egress router. Through simulations, we show that when the CPM scheme is employed, most of the attack packets in excess of the link capacity are dropped while less than 4% of the legitimate packets are dropped in typical scenarios. The simulation result also shows significantly improved TCP performance when CPM is utilized.
Keywords
Computational modeling; Computer crime; Computer networks; Computer science; IP networks; Information filtering; Information filters; Internet; Telecommunication traffic; Traffic control;
fLanguage
English
Publisher
ieee
Conference_Titel
Communications, 2006. ICC '06. IEEE International Conference on
Conference_Location
Istanbul
ISSN
8164-9547
Print_ISBN
1-4244-0355-3
Electronic_ISBN
8164-9547
Type
conf
DOI
10.1109/ICC.2006.255090
Filename
4024485
Link To Document