Scispace (Formerly Typeset)
  1. Home
  2. Topics
  3. Application layer DDoS attack
  4. 2007
  1. Home
  2. Topics
  3. Application layer DDoS attack
  4. 2007
Showing papers on "Application layer DDoS attack published in 2007"
Journal Article•10.1109/TPDS.2007.1111•
Collaborative Detection of DDoS Attacks over Multiple Network Domains

[...]

Yu Chen1, Kai Hwang2, Wei-Shinn Ku3•
Binghamton University1, University of Southern California2, Auburn University3
01 Dec 2007-IEEE Transactions on Parallel and Distributed Systems
TL;DR: This paper develops a distributed change-point detection (DCD) architecture using change aggregation trees (CAT), and proves that this DDoS defense system can scale well to cover 84 AS domains, wide enough to safeguard most ISP core networks from real-life DDoS flooding attacks.
Abstract: This paper presents a new distributed approach to detecting DDoS (distributed denial of services) flooding attacks at the traffic-flow level The new defense system is suitable for efficient implementation over the core networks operated by Internet service providers (ISPs). At the early stage of a DDoS attack, some traffic fluctuations are detectable at Internet routers or at the gateways of edge networks. We develop a distributed change-point detection (DCD) architecture using change aggregation trees (CAT). The idea is to detect abrupt traffic changes across multiple network domains at the earliest time. Early detection of DDoS attacks minimizes the floe cling damages to the victim systems serviced by the provider. The system is built over attack-transit routers, which work together cooperatively. Each ISP domain has a CAT server to aggregate the flooding alerts reported by the routers. CAT domain servers collaborate among themselves to make the final decision. To resolve policy conflicts at different ISP domains, a new secure infrastructure protocol (SIP) is developed to establish mutual trust or consensus. We simulated the DCD system up to 16 network domains on the Cyber Defense Technology Experimental Research (DETER) testbed, a 220-node PC cluster for Internet emulation experiments at the University of Southern California (USC) Information Science Institute. Experimental results show that four network domains are sufficient to yield a 98 percent detection accuracy with only 1 percent false-positive alarms. Based on a 2006 Internet report on autonomous system (AS) domain distribution, we prove that this DDoS defense system can scale well to cover 84 AS domains. This security coverage is wide enough to safeguard most ISP core networks from real-life DDoS flooding attacks.

314 citations

Proceedings Article•10.1109/ICSCN.2007.350758•
A Distributed Approach using Entropy to Detect DDoS Attacks in ISP Domain

[...]

Krishan Kumar1, Rajesh Joshi1, K. Singh1•
Indian Institute of Technology Roorkee1
5 Nov 2007
TL;DR: It is proposed to distribute these overheads amongst all POPs of the ISP using an ISP level traffic feature distribution based approach and the comparison with volume based approach clearly indicates the supremacy of the proposed methodology.
Abstract: DDoS attacks are best detected near the victim's site as maximum attack traffic converges at this point. In most of the current solutions, monitoring and analysis of traffic for DDoS detection have been carried at a single link which connects victim to ISP. However the mammoth volume generated by DDoS attacks pose the biggest challenge in terms of memory and computational overheads. These overheads make DDoS solution itself vulnerable against DDoS attacks. We propose to distribute these overheads amongst all POPs of the ISP using an ISP level traffic feature distribution based approach. An ISP level topology and well known attack tools are used for simulations in ns-2. The comparison with volume based approach clearly indicates the supremacy of the proposed methodology

102 citations

Journal Article•10.1016/J.COMNET.2007.08.008•
Robust and efficient detection of DDoS attacks for large-scale internet

[...]

Kejie Lu1, Dapeng Wu2, Jieyan Fan2, Sinisa Todorovic3, Antonio Nucci4 •
University of Puerto Rico at Mayagüez1, University of Florida2, University of Illinois at Urbana–Champaign3, Narus4
01 Dec 2007-Computer Networks
TL;DR: A novel framework to robustly and efficiently detect DDoS attacks and identify attack packets without modifying existing IP forwarding mechanisms at routers is proposed, in which traffic is analyzed only at the edge routers of an internet service provider (ISP) network.

102 citations

Proceedings Article•10.1109/ICIMP.2007.42•
Smurf-based Distributed Denial of Service (DDoS) Attack Amplification in Internet

[...]

Sanjeev Kumar1•
University of Texas at Austin1
1 Jul 2007
TL;DR: It is shown in this paper that utilizing this attack, it is possible for an attacker to just use a dialup modem and an unprotected intermediary network to exhaust even an ultra high speed optical line such as OC-192 of the victim network.
Abstract: The Smurf-based distributed denial of service (DDoS) attack is an amplification attack where the attacker uses unprotected intermediate networks to amplify the attack traffic load and direct it to the victim computer. In this paper, we investigate the factors that contribute to the amplification of the smurf attack traffic and understand the relation among the original attack traffic, intermediate unprotected network and the final amplified attack traffic. We also define a new term called attack amplification factor which represents the degree of amplification that original attack traffic undergoes during its transmission towards the victim computer. It is also shown in this paper that utilizing this attack, it is possible for an attacker to just use a dialup modem and an unprotected intermediary network to exhaust even an ultra high speed optical line such as OC-192 of the victim network.

100 citations

Proceedings Article•10.1109/ICNS.2007.5•
A Detection and Offense Mechanism to Defend Against Application Layer DDoS Attacks

[...]

Jie Yu1, Zhoujun Li, Huowang Chen1, Xiaoming Chen2•
National University of Defense Technology1, Beihang University2
19 Jun 2007
TL;DR: A mechanism named as DOW (defense and offense wall), which defends against layer-7 attacks using combination of detection technology and currency technology, and an encouragement model that uses client's session rate as currency to defend against session-flooding attacks.
Abstract: Application layer DDoS attacks, which are legitimate in packets and protocols, gradually become a pressing problem for commerce, politics and military. We build an attack model and characterize layer-7 attacks into three classes: session flooding attacks, request flooding attacks and asymmetric attacks. We proposed a mechanism named as DOW (defense and offense wall), which defends against layer-7 attacks using combination of detection technology and currency technology. An anomaly dete-ction method based on K-means clustering is introduced to detect and filter request flooding attacks and asymmetric attacks. To defend against session-flooding attacks, we propose an encouragement model that uses client's session rate as currency. Detection model drops suspicious sessions, while currency model encourages more legitimate sessions. By collaboration of these two models, normal clients could gain higher service rate and lower delay of response time.

77 citations

Proceedings Article•10.1109/ICC.2007.206•
Machine Learning for Automatic Defence Against Distributed Denial of Service Attacks

[...]

S. Seufert1, Darragh O'Brien1•
Dublin City University1
24 Jun 2007
TL;DR: The goal of this paper is to explore the effectiveness of machine learning techniques in developing automatic defences against DDoS attacks by developing a data collection and traffic filtering framework and exploring the potential of artificial neural networks in the defence againstDDoS attacks.
Abstract: Distributed denial of service attacks pose a serious threat to many businesses which rely on constant availability of their network services. Companies like Google, Yahoo and Amazon are completely reliant on the Internet for their business. It is very hard to defend against these attacks because of the many different ways in which hackers may strike. Distinguishing between legitimate and malicious traffic is a complex task. Setting up filtering by hand is often impossible due to the large number of hosts involved in the attack. The goal of this paper is to explore the effectiveness of machine learning techniques in developing automatic defences against DDoS attacks. As a first step, a data collection and traffic filtering framework is developed. This foundation is then used to explore the potential of artificial neural networks in the defence against DDoS attacks.

77 citations

Journal Article•10.1109/TPDS.2007.1014•
A Divide-and-Conquer Strategy for Thwarting Distributed Denial-of-Service Attacks

[...]

Ruiliang Chen, Jung-Min Park, Randy Marchany
01 May 2007-IEEE Transactions on Parallel and Distributed Systems
TL;DR: Attack diagnosis (AD) is presented, a novel attack mitigation scheme that adopts a divide-and-conquer strategy and is shown to be robust against IP spoofing and to incur low false positive ratios.
Abstract: Attack mitigation schemes actively throttle attack traffic generated in distributed denial-of-service (DDoS) attacks. This paper presents attack diagnosis (AD), a novel attack mitigation scheme that adopts a divide-and-conquer strategy. AD combines the concepts of pushback and packet marking, and its architecture is in line with the ideal DDoS attack countermeasure paradigm - attack detection is performed near the victim host and packet filtering is executed close to the attack sources. AD is a reactive defense mechanism that is activated by a victim host after an attack is detected. By instructing its upstream routers to mark packets deterministically, the victim can trace back one attack source and command an AD-enabled router close to the source to filter the attack packets. This process isolates one attacker and throttles it, which is repeated until the attack is mitigated. We also propose an extension to AD called parallel attack diagnosis (PAD) that is capable of throttling traffic coming from a large number of attackers simultaneously. AD and PAD are analyzed and evaluated using the Skitter Internet map, Lumeta's Internet map, and the 6-degree complete tree topology model. Both schemes are shown to be robust against IP spoofing and to incur low false positive ratios

70 citations

Book Chapter•10.1007/978-3-540-71549-8_17•
Defending DDoS attacks using hidden Markov models and cooperative reinforcement learning

[...]

Xin Xu1, Yongqiang Sun1, Zunguo Huang1•
National University of Defense Technology1
11 Apr 2007
TL;DR: A novel DDoS detection approach based on Hidden Markov Models (HMMs) and cooperative reinforcement learning is proposed, where a distributed cooperation detection scheme using source IP address monitoring is employed.
Abstract: In recent years, distributed denial of service (DDoS) attacks have brought increasing threats to the Internet since attack traffic caused by DDoS attacks can consume lots of bandwidth or computing resources on the Internet and the availability of DDoS attack tools has become more and more easy. However, due to the similarity between DDoS attack traffic and transient bursts of normal traffic, it is very difficult to detect DDoS attacks accurately and quickly. In this paper, a novel DDoS detection approach based on Hidden Markov Models (HMMs) and cooperative reinforcement learning is proposed, where a distributed cooperation detection scheme using source IP address monitoring is employed. To realize earlier detection of DDoS attacks, the detectors are distributed in the mediate network nodes or near the sources of DDoS attacks and HMMs are used to establish a profile for normal traffic based on the frequencies of new IP addresses. A cooperative reinforcement learning algorithm is proposed to compute optimized strategies of information exchange among the distributed multiple detectors so that the detection accuracies can be improved without much load on information communications among the detectors. Simulation results on distributed detection of DDoS attacks generated by TFN2K tools illustrate the effectiveness of the proposed method.

66 citations

Book Chapter•10.1007/978-0-387-72367-9_20•
A survey of bots used for distributed denial of service attacks

[...]

Vrizlynn L. L. Thing1, Morris Sloman1, Naranker Dulay1•
Imperial College London1
14 May 2007
TL;DR: A detailed study of the source code of the popular DDoS attack bots, Agobot, SDBot, RBot and Spybot, is presented to provide an in-depth understanding of the attacks in order to facilitate the design of more effective and efficient detection and mitigation techniques.
Abstract: In recent years, we have seen the arrival of Distributed Denial-of-Service (DDoS) open-source bot-based attack tools facilitating easy code enhancement, and so resulting in attack tools becoming more powerful. Developing new techniques for detecting and responding to the latest DDoS attacks often entails using attack traces to determine attack signatures and to test the techniques. However, obtaining actual attack traces is difficult, because the high-profile organizations that are typically attacked will not release monitored data as it may contain sensitive information. In this paper, we present a detailed study of the source code of the popular DDoS attack bots, Agobot, SDBot, RBot and Spybot to provide an in-depth understanding of the attacks in order to facilitate the design of more effective and efficient detection and mitigation techniques.

64 citations

Patent•
Methods and apparatus providing computer and network security for polymorphic attacks

[...]

Jeffrey A. Kraemer1, Andrew Zawadowskiy1•
Cisco Systems, Inc.1
30 Apr 2007
TL;DR: In this article, a system detects an attack on a computer system and adjusts access to an interface to prevent further damage caused to the computer system by the attack, which is called polymorphic polymorphism.
Abstract: A system detects an attack on the computer system. The system identifies the attack as polymorphic, capable of modifying itself for every instance of execution of the attack. The modification of the attack is utilized to defeat detection of the attack. In one embodiment, the system determines generation of an effective signature of the attack has failed. The signature is utilized to prevent execution of the attack. The system then adjusts access to an interface to prevent further damage caused to the computer system by the attack.

53 citations

Proceedings Article•10.1109/ICCGI.2007.61•
Typical DoS/DDoS Threats under IPv6

[...]

Xinyu Yang1, Ting Ma1, Yi Shi1•
Xi'an Jiaotong University1
4 Mar 2007
TL;DR: This paper focuses on the typical DoS/DDoS attacks under IPv6, which including the DoS attacks pertinent to IPv6 Neighbor Discovery protocol and DDoS attacks based on the four representative attack modes, they are respectively TCP-Flood, UDP-Fl Flood, ICMP-Fl flood and Smurf.
Abstract: The DoS/DDoS attacks are always the leading threats to the Internet. With the development of Internet, IPv6 is inevitably taking the place of IPv4 as the main protocol of Internet. So the security issues of IPv6 become the focus of the present research. In this paper we mainly focus on the typical DoS/DDoS attacks under IPv6, which including the DoS attacks pertinent to IPv6 Neighbor Discovery protocol and DDoS attacks based on the four representative attack modes, they are respectively TCP-Flood, UDP-Flood, ICMP-Flood and Smurf. We do these attack experiments under IPv6 with and without IPSec configuration respectively. The experiments without IPSec validate the effectiveness of the typical DoS/DDoS attacks under IPv6, and those with IPSec show the effectiveness of IPSec against these attacks whose source addresses are spoofed.
Journal Article•10.1145/1189740.1189745•
Defeating DDoS attacks by fixing the incentive chain

[...]

Yun Huang1, Xianjun Geng2, Andrew B. Whinston1•
University of Texas at Austin1, University of Washington2
01 Feb 2007-ACM Transactions on Internet Technology
TL;DR: This article discusses two components of the technological solutions to DDoS attacks: cooperative filtering and cooperative traffic smoothing by caching and proposes usage-based pricing and Capacity Provision Networks, which enable victims to disseminate enough incentive along attack paths to stimulate cooperation against DDoS attack.
Abstract: Cooperative technological solutions for Distributed Denial-of-Service (DDoS) attacks are already available, yet organizations in the best position to implement them lack incentive to do so, and the victims of DDoS attacks cannot find effective methods to motivate them. In this article we discuss two components of the technological solutions to DDoS attacks: cooperative filtering and cooperative traffic smoothing by caching. We then analyze the broken incentive chain in each of these technological solutions. As a remedy, we propose usage-based pricing and Capacity Provision Networks, which enable victims to disseminate enough incentive along attack paths to stimulate cooperation against DDoS attacks.
Journal Article•
Pulsing RoQ DDoS Attack and Defense Scheme in Mobile Ad Hoc Networks

[...]

Wei Ren1•
Hong Kong University of Science and Technology1
01 Jan 2007-International Journal of Network Security
TL;DR: This paper study in detail congestion-based RoQ DDoS attacks in mobile ad-hoc networks for the first time and proposes a defense scheme that includes both the detection and response mechanisms.
Abstract: Reduction of Quality (RoQ) attack is a new style of Distributed Denial of Service (DDoS) attack. The goodput and delay performance of TCP or UDP flows are very sensitive to such RoQ attacks. In this paper, we study in detail congestion-based RoQ DDoS attacks in mobile ad-hoc networks for the first time. Specifically, we study the attacking principles based on analysis of the network capacity and classify these attacks into four categories: pulsing attack, round robin attack, self-whisper attack, and flooding attack. We then propose a defense scheme that includes both the detection and response mechanisms. The detection signals include the frequency of receiving RTS/CTS packets, frequency of sensing a busy channel (signal interference), and number of RTS/DATA retransmissions. The response scheme is based on the ECN marking mechanism. Through extensive ns2 network simulations, we demonstrate the existence of high goodput and delay jitters under the pulsing attack mode. Increase in delay (by 110 times under five attacking flows) and decrease in goodput (to 77% under five attacking flows) can be observed especially when more attacking flows occurs. Moreover, we show through simulations that similar behaviors can also be observed for TCP flows as well as networks of other topology types.
Proceedings Article•10.1109/ADCOM.2007.28•
Accurate ICMP TraceBack Model under DoS/DDoS Attack

[...]

Alireza Izaddoost, Mohamed Othman, Mohd Fadlee A. Rasid
18 Dec 2007
TL;DR: A model considering incoming packets routed to the victim and by modifying intention-driven iTrace model, this paper can generate more effective ICMP traceback packets to locate the source of attack more accurately.
Abstract: One of the most significant current groups of security endangerments in the Internet is DoS/DDoS attacks. The goal of these kinds of attacks is to completely engage available resources so that legitimate users are not able to access a service. Some traceback approach has been proposed to traceback source of attack. One of these methods is Intention-driven iTrace which is the working base of the ICMP traceback. By this method, it will be possible to increase effective ICMP traceback messages which can provide useful information to the victim in tracing source of attack. Reconstructed path to the source of attack by the victim can be done accurately when more effective ICMP traceback messages are generated in critical routers. In this paper, we proposed a model considering incoming packets routed to the victim and by modifying intention-driven iTrace model, we can generate more effective ICMP traceback packets to locate the source of attack more accurately.
Proceedings Article•10.1109/IPC.2007.28•
A Study of Defense DDoS Attacks Using IP Traceback

[...]

Cheol-Joo Chae1, Seoung-Hyeon Lee, Jae Seung Lee, Jae-Kwang Lee•
Hannam University1
11 Oct 2007
TL;DR: This work proposes security framework using IP Traceback being able to response DDoS attack, and shows that proposed security framework is safe to deploy and protect data in network from attackers and others.
Abstract: DDoS(distributed denial of service) attack is a critical threat to current Internet Recently too many technologies of the detection and prevention have developed, but it is difficult that the IDS distinguishes normal traffic from the DDoS attack Therefore, when the DDoS attack is detected by IDS, the firewall just discards all over-bounded traffic for a victim of absolutely decreases the threshold of the router Also, Attacker use spoofing IP address To solve this problem, we propose security framework using IP Traceback being able to response DDoS attack Our Implementation shows that proposed security framework is safe to deploy and protect data in network from attackers and others
Book Chapter•10.1007/978-3-540-77048-0_35•
DDoS attack detection algorithms based on entropy computing

[...]

Liying Li1, Jianying Zhou2, Ning Xiao3•
National University of Singapore1, Institute for Infocomm Research Singapore2, Symantec3
12 Dec 2007
TL;DR: The previous entropy detection algorithm is improved, and two enhanced detection methods based on cumulative entropy and time, respectively are proposed, which could lead to more accurate and effective DDoS detection.
Abstract: Distributed Denial of Service (DDoS) attack poses a severe threat to the Internet. It is difficult to find the exact signature of attacking. Moreover, it is hard to distinguish the difference of an unusual high volume of traffic which is caused by the attack or occurs when a huge number of users occasionally access the target machine at the same time. The entropy detection method is an effective method to detect the DDoS attack. It is mainly used to calculate the distribution randomness of some attributes in the network packets' headers. In this paper, we focus on the detection technology of DDoS attack. We improve the previous entropy detection algorithm, and propose two enhanced detection methods based on cumulative entropy and time, respectively. Experiment results show that these methods could lead to more accurate and effective DDoS detection.
Proceedings Article•
AS-based accountability as a cost-effective DDoS defense

[...]

Daniel R. Simon1, Sharad Agarwal1, David A. Maltz1•
Microsoft1
10 Apr 2007
TL;DR: In this article, the authors argue that the key to cost-effective handling of DDoS attacks on a network such as the Internet is accountability, meaning that the sources of all traffic can be accurately and reliably identified, and receivers can effectively block traffic to them from any source.
Abstract: Defenses against botnet-based distributed denial-of-service (DDoS) attacks must demonstrate that in addition to being technically feasible, they are also economically viable, particularly when compared with the two most widely deployed defenses--simple massive overprovisioning of resources to absorb and handle DDoS traffic, and "scrubbing" of incoming traffic by the victim's ISP. We argue that the key to cost-effective handling of DDoS attacks on a network such as the Internet is accountability, meaning that the sources of all traffic can be accurately and reliably identified, and receivers can effectively block traffic to them from any source. We propose a simple approach to directly providing accountability within a group of ASes. It combines strict ingress filtering on all edge traffic with an AS-based infrastructure that allows hosts to request that traffic to them from specific other hosts be blocked at the source. We also propose using the previously proposed "evil bit" in IP headers to allow a group of ASes that implement accountability to collectively reduce the impact of DDoS attacks originating outside their portion of the Internet. Finally, we present evidence for the economic competitiveness of our approach, compared with the current default approaches of massive overprovisioning and ISP scrubbing.
Journal Article•10.1016/J.JNCA.2005.07.005•
Provider-based deterministic packet marking against distributed DoS attacks

[...]

Vasilios A. Siris1, Ilias Stavrakis1•
Foundation for Research & Technology – Hellas1
01 Aug 2007-Journal of Network and Computer Applications
TL;DR: A rate control scheme that protects destination domains by limiting the amount of traffic during an attack, while leaving a large percentage of legitimate traffic unaffected is proposed.
Proceedings Article•10.1145/1229285.1229331•
Non-intrusive IP traceback for DDoS attacks

[...]

Vrizlynn L. L. Thing1, Morris Sloman1, Naranker Dulay1•
Imperial College London1
20 Mar 2007
TL;DR: A Non-Intrusive IP traceback scheme which uses sampled traffic under non-attack conditions to build and maintains caches of the valid source addresses transiting network routers, allowing for a fast traceback and the scheme is scalable due to the distribution of processing workload.
Abstract: The paper describes a Non-Intrusive IP traceback scheme which uses sampled traffic under non-attack conditions to build and maintains caches of the valid source addresses transiting network routers. Under attack conditions, route anomalies are detected by determining which routers have been used for unknown source addresses, in order to construct the attack graph. Results of simulation studies are presented. Our approach does not require changes to the Internet routers or protocols. Precise information regarding the attack is not required allowing a wide variety of DDoS attack detection techniques to be used. Our algorithm is simple and efficient, allowing for a fast traceback and the scheme is scalable due to the distribution of processing workload.
Journal Article•10.1016/J.JNCA.2005.07.006•
Enhanced Internet security by a distributed traffic control service based on traffic ownership

[...]

Matthias Bossardt1, Thomas Dübendorfer1, Bernhard Plattner1•
École Polytechnique Fédérale de Lausanne1
01 Aug 2007-Journal of Network and Computer Applications
TL;DR: The novel concept of traffic ownership is proposed and a system that extends control over network traffic by network users to the Internet using adaptive traffic processing devices is described, which safely delegate partial network management capabilities from network operators to network users.
Journal Article•10.1093/IETCOM/E90-B.10.2655•
Collaborative Defense Mechanism Using Statistical Detection Method against DDoS Attacks

[...]

Byung-Hak Song1, Joon Heo1, Choong Seon Hong1•
Kyung Hee University1
01 Oct 2007-IEICE Transactions on Communications
TL;DR: This paper suggests the effective DDoS defense system which uses the collaborative scheme among distributed IDRSs located in the vicinity of the attack source or victim network.
Abstract: Distributed Denial-of-Service attack (DDoS) is one of the most outstanding menaces on the Internet. A DDoS attack generally attempts to overwhelm the victim in order to deny their services to legitimate users. A number of approaches have been proposed for defending against DDoS attacks accurately in real time. However, existing schemes have limits in terms of detection accuracy and delay if the IDRS (Intrusion Detection and Response System) deployed only at a specific location detects and responds against attacks. As in this case, it is not able to catch the characteristic of the attack which is distributed in large-scale. Moreover, the existing detection schemes have vulnerabilities to intellectual DDoS attacks which are able to avoid its detection threshold or delay its detection time. This paper suggests the effective DDoS defense system which uses the collaborative scheme among distributed IDRSs located in the vicinity of the attack source or victim network. In proposed scheme, both victim and source-end IDRS work synergistically to identify the attack and avoid false alarm rate up to great extent. Additionally, we propose the duplicate detection window scheme to detect various attacks dynamics which increase the detection threshold gradually in early stage. The proposed scheme can effectively detect and respond against these diverse DDoS attack dynamics.
Journal Article•10.1093/COMJNL/BXL042•
An Inline Detection and Prevention Framework for Distributed Denial of Service Attacks

[...]

Zhongqiang Chen1, Zhongrong Chen, Alex Delis2•
New York University1, National and Kapodistrian University of Athens2
01 Jan 2007-The Computer Journal
TL;DR: The DDoS Container is proposed, a comprehensive framework that uses network-based detection methods to overcome the above complex and evasive types of attacks and shows its effectiveness in classifying DDoS traffic.
Abstract: By penetrating into a large number of machines and stealthily installing malicious pieces of code, a distributed denial of service (DDoS) attack constructs a hierarchical network and uses it to launch coordinated assaults. DDoS attacks often exhaust the network bandwidth, processing capacity and information resources of victims, thus, leading to unavailability of computing systems services. Various defense mechanisms for the detection, mitigation and/or prevention of DDoS attacks have been suggested including resource redundancy, traceback of attack origins and identification of programs with suspicious behavior. Contemporary DDoS attacks employ sophisticated techniques including formation of hierarchical networks, one-way communication channels, encrypted messages, dynamic ports allocation and source address spoofing to hide the attackers' identities; such techniques make both detection and tracing of DDoS activities a challenge and render traditional DDoS defense mechanisms ineffective. In this paper, we propose the DDoS Container, a comprehensive framework that uses network-based detection methods to overcome the above complex and evasive types of attacks; the framework operates in 'inline' mode to inspect and manipulate ongoing traffic in real-time. By keeping track of connections established by both potential DDoS attacks and legitimate applications, the suggested DDoS Container carries out stateful inspection on data streams and correlates events among sessions. The framework performs stream re-assembly and dissects the resulting aggregations against protocols followed by various known DDoS attacks facilitating their identification. The traffic pattern analysis and data correlation of the framework further enhance its detection accuracy on DDoS traffic camouflaged with encryption. Actions available on identified DDoS traffic range from simple alerting to message blocking and proactive session termination. Experimentation with the prototype of our DDoS Container shows its effectiveness in classifying DDoS traffic.
Journal Article•10.1016/J.ADHOC.2006.04.002•
Analysis of area-congestion-based DDoS attacks in ad hoc networks

[...]

Qijun Gu1, Peng Liu2, Chao-Hsien Chu2•
Texas State University1, Pennsylvania State University2
1 Jul 2007
TL;DR: This paper examines two types of area-congestion-based DDoS attacks - remote and local attacks - and presents in-depth analysis on various factors and attack constraints that an attacker may use and face.
Abstract: Increased instances of distributed denial of service (DDoS) attacks on the Internet have raised questions on whether and how ad hoc networks are vulnerable to such attacks. This paper studies the special properties of such attacks in ad hoc networks. We examine two types of area-congestion-based DDoS attacks - remote and local attacks - and present in-depth analysis on various factors and attack constraints that an attacker may use and face. We find that (1) there are two types of congestion - self congestion and cross congestion - that need to be carefully monitored; (2) the normal traffic itself causes significant packet loss in addition to the attack impacts in both remote and local attacks; (3) the number of flooding nodes has major impacts on remote attacks while, the load of normal traffic and the position of flooding nodes are critical to local attacks; and (4) given the same number of flooding nodes and attack loads, a remote DDoS attack can cause more damage to the network than a local DDoS attack.
Proceedings Article•10.1109/GRC.2007.73•
Generating Attack Scenarios with Causal Relationship

[...]

Yu-Chin Cheng1, Chien-Hung Chen1, Chung-Chih Chiang1, Jun-Wei Wang1, Chi-Sung Laih1 •
National Cheng Kung University1
2 Nov 2007
TL;DR: It is shown that the proposed system architecture to generate an attack scenario database correctly and completely is better than CAML since it can generate more attack scenarios effectively and correctly to help system managers to maintain network security.
Abstract: With the incoming of information era, Internet has been developed rapidly and offered more and more services However, intrusions, viruses and worms follow with the grown of Internet, spread widely all over the world within high speed network Although many kinds of intrusion detection systems (IDSs) are developed, they have some disadvantages in that they focus on low-level attacks or anomalies, and raise alerts independently In this paper, we give a formal description about attack patterns, attack transition states and attack scenarios We proposed the system architecture to generate an attack scenario database correctly and completely We first classify and extract attack patterns, then, correlate attack patterns with pre/post conditions matching and Moreover, the approach, attack scenario generation with casual relationship (ASGCR), is proposed to build an attack scenario database Finally, we present the combination of our attack scenario database with security operation center (SOC) to implement the related components concerning alert integrations and correlations It is shown that our method is better than CAML [4] since we can generate more attack scenarios effectively and correctly to help system managers to maintain network security
Patent•
DDoS FLOODING ATTACK RESPONSE APPROACH USING DETERMINISTIC PUSH BACK METHOD

[...]

Jungtaek Seo1, Kiwook Sohn1, Eungki Park1•
Electronics and Telecommunications Research Institute1
25 Sep 2007
TL;DR: In this article, a deterministic pushback scheme is proposed to respond to DDoS attacks using the IP address information of an attack source edge router, which is obtained by reassembling an IP address of detected DDoS attack packets at a victim system that detects DDoS.
Abstract: Provided is a method for responding a distributed denial of service (DDoS) attack using deterministic pushback scheme. In the method, all of packets outbound from an edge router of a predetermined network system to the other network system are marked with own IP address in order to enable a victim system to confirm an IP address of an attack source edge router for DDoS attack packets. Then, IP address information of an attack source edge router is obtained by reassembling an IP address of detected DDoS attack packets at a victim system that detects DDoS attack. A deterministic pushback message is received at an attack source edge router if a victim system transmits a deterministic pushback message to the attack source edge router, information of the attack source edge router is confirmed, and corresponding attack packets are filtered.
Proceedings Article•10.1109/ICWS.2007.23•
A SOA Approach to Counter DDoS Attacks

[...]

Xinfeng Ye1, S. Singh1•
University of Auckland1
9 Jul 2007
TL;DR: A SOA approach to build a system against DDoS attacks targeting online businesses is proposed, built on Web services and can be constructed and reconfigured easily by an attack victim.
Abstract: Distributed denial-of-service (DDoS) attacks are increasingly mounted by cyber-criminal gangs to extort money from online businesses. This kind of attacks is normally targeted at a particular service provider to exhaust the network and system resources of the provider. Since the scale of the attack is limited, the ISP operators normally cannot observe this type of attacks. As a result, the victim of the attack is left to deal with the attack on its own accord. This paper proposes a SOA approach to build a system against DDoS attacks targeting online businesses. The system is built on Web services. It can be constructed and reconfigured easily by an attack victim. Experiments were also carried out to measure the overheads and the effectiveness of the proposed approach.
Proceedings Article•10.1109/ITA.2007.4357573•
Optimal Allocation of Filters against DDoS Attacks

[...]

K. El Defrawy1, Athina Markopoulou1, Katerina Argyraki2•
University of California, Irvine1, École Polytechnique Fédérale de Lausanne2
22 Oct 2007
TL;DR: The results demonstrate that efficient filter allocation significantly improves the tradeoff between the number of filters used and the amount of legitimate traffic preserved.
Abstract: Distributed denial-of-service (DDoS) attacks are a major problem in the Internet today. During a DDoS attack, a large number of compromised hosts send unwanted traffic to the victim, thus exhausting the resources of the victim and preventing it from serving its legitimate clients. One of the main mechanisms against DDoS is filtering, which allows routers to selectively block unwanted traffic. Given the magnitude of DDoS attacks and the high cost of filters in the routers today, the successful mitigation of a DDoS attack using filtering crucially depends on the efficient allocation of filtering resources. In this paper, we consider a single router with a limited number of available filters. We study how to optimally allocate filters to attack sources, or entire domains of attack sources, so as to maximize the amount of good traffic preserved, under a constraint on the number of filters. First, we look at the single-tier problem, where the collateral damage on legitimate traffic is high due to the filtering at the granularity of attack domains. Second, we look at the two-tier problem, where we have an additional constraint on the number of filters and filtering is performed at the granularity of attackers and/or domains. We formulate both problems as optimization problems, and we evaluate the optimal solution over a range of realistic attack-scenarios. Our results demonstrate that efficient filter allocation significantly improves the tradeoff between the number of filters used and the amount of legitimate traffic preserved.
TCP Flow Analysis for Defense against Shrew DDoS Attacks

[...]

Yu Chen, Kai Hwang1•
University of Southern California1
1 Jan 2007
TL;DR: This paper proposes a novel defense scheme against shrew DDoS or RoQ (reduction-of-service) attacks, and reveals the spectral shifting of attack flows from that of normal flows.
Abstract: - The shrew or RoS attacks are low-rate DDoS attacks that degrade the QoS to end systems slowly but not to deny the services completely. These attacks are more difficult to detect than the flooding type of DDoS attacks. In this paper, we explore the energy distributions of Internet traffic flows in frequency domain. Normal TCP traffic flows present some form of periodicity because of TCP protocol behavior. Our results reveal that normal TCP flows can be segregated from malicious flows using some energy distribution properties. We discover the spectral shifting of attack flows from that of normal flows. Combining flow-level spectral analysis with sequential hypothesis testing, we propose a novel defense scheme against shrew DDoS or RoQ (reduction-of-service) attacks. Our detection and filtering scheme can effectively rescue 99% legitimate TCP flows under the RoS attacks. Keywords: Network security, Internet traffic spectrum, low-rate DDoS attacks, reduction-of-quality attacks, digital signal processing, spectral analysis.
Journal Article•10.3844/AJASSP.2007.741.745•
A Novel Packet Marketing Method in DDoS Attack Detection

[...]

Changhyun Beak1, Junaid Ahsenali Chaudhry, Keonsoo Lee1, Seung-Kyu Park1, Minkoo Kim1 •
Ajou University1
31 Oct 2007-American Journal of Applied Sciences
TL;DR: A Link-ID was the in-formation of path between Border Gateway Protocol routers in the Autonomic Systems and each BGP router's connection to the outside of the AS and this shows promising results if compared with contemporary filtering methods.
Abstract: Functionality and availability are one of the main characteristics of internet and hence very inviting for attackers to try to provoke a denial-of-service attack. As the intensity and frequency of DDoS attacks has increased, various preventive mechanisms have also been proposed. One of the most effective defence mechanisms proposed was Path Identification (Pi). This method tracks the packet transmission path. With this packets carrying path information, the victim node can defend itself from DDoS attack by filtering the packets transmitting via/from an attacking node. The Pi method has advantages such as trivial operation, filtering on a per-packet and independency on router for blocking over the other trace back methods etc. As the Pi method uses the router's IP address to construct the path information of each packet, which was stored in each packet's ID field. However, because of the limitation of the ID field, only two bits of resulted message digest of router's IP address are used, which results in same path information representing different paths. To ad-dress this problem, we propose using Link-ID's instead of IP addresses or routers to construct the path information of each packet. A Link-ID was the in-formation of path between Border Gateway Protocol (BGP) routers in the Autonomic Systems (AS) and each BGP router's connection to the outside of the AS. Further analysis shows promising results if compared with contemporary filtering methods.
Proceedings Article•10.1109/LCN.2007.11•
A Game-Theoretic Framework for Bandwidth Attacks and Statistical Defenses

[...]

Mark Edward Snyder1, Ravi Sundaram2, M. Thakur1•
Missouri University of Science and Technology1, Northeastern University2
15 Oct 2007
TL;DR: The results show that there is potential for using statistical methods for creating defense mechanisms that can detect a DDoS attack and that even when an attacker has a priori knowledge of the expected traffic volume for the dimension and divisions employed in the attack, the attack traffic can still be exposed to the defender.
Abstract: We introduce a game-theoretic framework for reasoning about bandwidth attacks, a common form of distributed denial of service (DDoS) attacks. In particular, our traffic injection game models the attacker as a rational but limited-resource entity who uses limited knowledge of traffic patterns to launch IP spoofing based bandwidth attacks on a server. We model the defender as a coarse-grained, relative volume based statistical filter. We analyze the effectiveness of the defender against the attacker by analyzing the payoffs of various strategies in the traffic injection game. Furthermore, we analyze how these payoffs change in the presence of random noise. Our results show that there is potential for using statistical methods for creating defense mechanisms that can detect a DDoS attack and that even when an attacker has a priori knowledge of the expected traffic volume for the dimension and divisions employed in the attack, the attack traffic can still be exposed to the defender.

Tools

SciSpace AgentBiomedical AgentSciSpace RecruitSciSpace for EnterpriseAgent GalleryChat with PDFLiterature ReviewAI WriterFind TopicsParaphraserCitation GeneratorExtract DataAI DetectorCitation Booster

Learn

ResourcesLive Workshops

SciSpace

CareersSupportBrowse PapersPricingSciSpace Affiliate ProgramCancellation & Refund PolicyTermsPrivacyData Sources

Directories

PapersTopicsJournalsAuthorsConferencesInstitutionsCitation StylesWriting templates

Extension & Apps

SciSpace Chrome ExtensionSciSpace Mobile App

Contact

support@scispace.com
SciSpace

© 2026 | PubGenius Inc. | Suite # 217 691 S Milpitas Blvd Milpitas CA 95035, USA

soc2
Secured by Delve