Resistance against Distributed Denial of Service Attacks (DDoS) Using Bandwidth Based Admission Control
V.Shyamala Devi, R. S. D. Wahidabanu, Dr.K. Duraisway · International Journal of Computer Applications · 2010
Internet hosts are threatened by large-scale Distributed Denial of-Service (DDoS) attacks. The Path Identification DDoS defense scheme has recently been proposed as a deterministic packet marking scheme that allows a DDoS victim to filter out attack packets on a per packet basis with high accuracy after only a few attack packets are received. The previous work suggested depicts the Stack Path identification marking, a packet marking scheme based on path identification, and filtering mechanisms. To circumvent detection, attackers are increasingly moving from floods to attacks that mimic the behavior of a large number of clients, and target expensive higher-layer resources such as CPU, database and disk bandwidth. The resulting attacks are hard to defend against using standard techniques, as the malicious requests differ from the legitimate ones in intent but not in