Active ingress monitoring (AIM): an intrusion isolation scheme in active networks
G. Kim, T. Bogovic · 2002
Denial of Service (DoS) attacks have proven to be a challenging issue for the Internet community. We present a novel approach, active ingress monitoring (AIM), to effectively isolate DoS attacks that use randomly forged source IP addresses. Unlike the existing approaches, AIM reduces the computational overloads by executing the monitoring and filtering operations on selected packet streams only when needed. In addition, our scheme does not require complicated requirements or mandatory participation from every individual network in the Internet. AIM is based on the active networks environment and operates in the network layer based on passive traffic monitoring.