• DocumentCode
    64669
  • Title

    A router based packet filtering scheme for defending against DoS attacks

  • Author

    Lu Ning ; Su Sen ; Jing Maohua ; Han Jian

  • Author_Institution
    Sch. of Comput. & Commun. Eng., Northeastern Univ. at Qinhuangdao, Qinhuangdao, China
  • Volume
    11
  • Issue
    10
  • fYear
    2014
  • fDate
    Oct. 2014
  • Firstpage
    136
  • Lastpage
    146
  • Abstract
    The filter-based reactive packet filtering is a key technology in attack traffic filtering for defending against the Denial-of-Service (DoS) attacks. Two kinds of relevant schemes have been proposed as victim-end filtering and source-end filtering. The first scheme prevents attack traffic from reaching the victim, but causes the huge loss of legitimate flows due to the scarce filters (termed as collateral damages); the other extreme scheme can obtain the sufficient filters, but severely degrades the network transmission performance due to the abused filtering routers. In this paper, we propose a router based packet filtering scheme, which provides relatively more filters while reducing the quantity of filtering routers. We implement this scheme on the emulated DoS scenarios based on the synthetic and real-world Internet topologies. Our evaluation results show that compared to the previous work, our scheme just uses 20% of its filtering routers, but only increasing less than 15 percent of its collateral damage.
  • Keywords
    Internet; computer network security; telecommunication network routing; telecommunication network topology; telecommunication traffic; DoS attacks; Internet topologies; abused filtering routers; attack traffic filtering; denial-of-service attacks; filter-based reactive packet filtering; network transmission performance; router based packet filtering scheme; source-end filtering; victim-end filtering; Denial of Service; Filters; Information filters; Internet; Network security; Packet switching; Telecommunication traffic; DoS attacks; Internet security; filter-based reactive packet filtering;
  • fLanguage
    English
  • Journal_Title
    Communications, China
  • Publisher
    ieee
  • ISSN
    1673-5447
  • Type

    jour

  • DOI
    10.1109/CC.2014.6969802
  • Filename
    6969802