arrow
返回

Provider-based deterministic packet marking against distributed DoS attacks

delete2007-08-01
delete12
PRE
AI
V
Vasilios A. Siris *
DOI:10.1016/j.jnca.2005.07.005delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
One of the most serious security threats on the Internet are Distributed Denial of Service (DDoS) attacks, due to the significant service disruption they can create and the difficulty in preventing them. In this paper, we propose new deterministic packet marking models in order to characterize DDoS attack streams. Such a common characterization can be used to make filtering near the victim more effective. In this direction we propose a rate control scheme that protects destination domains by limiting the amount of traffic during an attack, while leaving a large percentage of legitimate traffic unaffected. The above features enable providers to offer enhanced security protection against such attacks as a value-added service to their customers, and hence offer positive incentives for them to deploy the proposed models. We evaluate the proposed marking models using a snapshot of the actual Internet topology, in terms of how well they differentiate attack traffic from legitimate traffic in cases of full and partial deployment. (C) 2005 Elsevier Ltd. All rights reserved.
Keyword:
Distributed Denial of Service (DDoS)
defense models
filtering
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

Journal of Network and Computer Applications 封面图
Journal of Network and Computer Applications
IF:
8
论文数:
3.6K
被引数:
1.1W

机构

暂无机构信息