Optimal filtering for denial of service mitigation

B. Stephan · 2003

An optimal approach to mitigation of denial of service flooding attacks is presented. The objective is to protect the server while minimizing the effect of the mitigation. The approach relies on routers filtering enough packets so that the server is not overwhelmed while ensuring that as little filtering as possible is performed. The optimal solution is to filter packets at routers through which the "attack packets" are passing. The identification of which router is forwarding the packets is carried out by routers filtering packets at time varying ratios. Then the correlation between the arrival of packets at the server and the router filtering ratios provides an indication of which routers are forwarding the attack packets. Once sufficient confidence in the identification is achieved, the routers that forward more attack packets will filter more packets than routers that forward less attack packets.

Read the paper · More papers on PaperTik