A two-tier coordinated defense scheme against DDoS attacks

Chin‐Ling Chen, Chih-Yu Chang · 2011

Distributed denial-of-service (DDoS) attacks can be regarded as the most serious threats for current Internet. This paper presents a two-tier coordination approach for detecting and mitigating DDoS attacks. The first tier traffic filter (1st-TF) filters suspicious traffic for possible flooding. This is achieved by using proactive tests to identify and isolate the malicious traffic. The second tier traffic filter (2nd-TF), which is deployed on network routers, performs online monitoring on queue length status with RED/Droptail mechanism for any incoming traffic. The simulation shows that the scheme can detect attacks accurately and effectively.

Read the paper · More papers on PaperTik