An Intelligent agent based defense architecture for DDoS attacks
M. Duraipandian, Chenniappan Palanisamy · 2014
By sending large amount of data flows from multiple sites, Distributed Denial-of-Service (DDoS) attacks target the victims. Many of the DDoS defense methods need to be implemented simultaneously and collaboratively on several nodes, making them difficult to implement, especially on nodes that need to maintain round-the-clock Internet connectivity. The defense methods rely on random or probabilistic means to detect illegitimate traffic and discard it, which necessitates that a certain percentage of legitimate packets be dropped in the process, reducing the overall Quality of Service. In this paper we propose an Intelligent Agent Based Defense Architecture for DDoS Attacks. It is fully distributed and provides an early warning when pre-attack activities are detected, using trust mechanisms. The proposed architecture also includes an improvement of Hop-Count Filtering (HCF) technique. By simulation results, we will show that the proposed architecture achieves high throughput with low packet drop, by detecting and isolating the attack traffic flows.