A practice of the intrusion prevention system
Lih‐Chyau Wuu, Yen‐Hung Chen, Chih-Chieh Ma, I-Tao Lung · 2007
Distributed Denial of Service (DDoS) attack is the most difficult to prevent on Internet. It occupies the network bandwidth or systems resources or both, to cause a system not to provide normal services to legal users, and even worse it crashes the whole system. Some researchers propose the source- end defense method trying to block the attack packets before they enter the Internet backbone. In this paper, we design an intrusion prevention system to realize the source-end defense method. The packets are categorized into three types: normal, suspicious and attack packets. The attack packets are blocked before they enter the Internet. The bandwidth of the suspicious packets is restricted and the IP header is attached with a signature made by their edge router. When a victim confirms the suspicious packets with an attack action, it finds out the source of the attack by the signature on the packets and then informs their edge router to block such packets.