Abstract
Distributed Denial of Service attacks prevent legitimate users from accessing a target machine or the service a target machine provides. One common method of attack is overwhelming the target machine with a large volume of traffic. Thus, handling congestion indirectly leads to detection and recovery from Distributed Denial of Service attacks. The Internet is an interconnected collection of Autonomous Systems. Every host on an Autonomous System connects to the Internet through an Access Router. Monitoring the rate of packets to and from a host, at the Access Router, helps in identifying Distributed Denial of Service attacks initiated at the host. Monitoring every Access Router leads to an effective Distributed Denial of Service prevention, but is infeasible. An alternative is a combination of Access Router monitoring and Intermediate Router monitoring with a novel Push-Forward mechanism that provides good defense within manageable deployment requirements. Push-Forward messages reduce the amount of traffic to monitor at the Intermediate Routers. Prototype testing and simulations of such a combination reveal good congestion detection and recovery time with very little performance overhead.
Original language | English (US) |
---|---|
Title of host publication | GLOBECOM - IEEE Global Telecommunications Conference |
Pages | 2055-2060 |
Number of pages | 6 |
Volume | 4 |
State | Published - 2004 |
Event | GLOBECOM'04 - IEEE Global Telecommunications Conference - Dallas, TX, United States Duration: Nov 29 2004 → Dec 3 2004 |
Other
Other | GLOBECOM'04 - IEEE Global Telecommunications Conference |
---|---|
Country/Territory | United States |
City | Dallas, TX |
Period | 11/29/04 → 12/3/04 |
ASJC Scopus subject areas
- Engineering(all)