Destination Address Monitoring Scheme for Detecting DDoS Attack in Centralized Control Network
Sang-Heon Shim, Kyoung-Min Yoo, Kyeong‐Eun Han, Chol-Ku Kang, Won-Ho So, Jongtae Song, Young-Chon Kim · 2006
As DDoS (distributed denial of service) attack becomes more diversified, the conventional detection methods based on single source router can't detect the attack efficiently. In order to combat this problem, centralized control is required to analyze and collect traffic generated in several source routers. This paper presents defense/detection scenario to protect against DDoS attack in centralized control network. A destination address monitoring scheme is also proposed to detect DDoS attacks in real-time. It measures the number of packets with same destination IP address by using modified Bloom filter. Because the modified Bloom filter uses extra table that manages relation among each address fields of destination IP address, it can reduce wrong detection rate. Simulation result shows the proposed scheme reduces the wrong detection rate than the conventional one