DDoSniffer: Detecting DDoS attack at the source agents

Vicky Laurens, Alexandre Miège, Abdulmotaleb El Saddik, Pulak Dhar · International Journal of Advanced Media and Communication · 2009

Distributed Denial of Service (DDoS) attacks are an important and challenging security threat. Despite the existing defence mechanisms, attackers manage to build large sets of impersonated hosts. Our approach consists in detecting DDoS directly on these hosts. We classify ongoing attacks as connection attacks or bandwidth attacks. The former are defined as attacks that generate connections with four packets or fewer; the latter as attacks that create connections with traffic ratios larger than usual. We developed a software tool, DDoSniffer, which enforces those principles. We show that it is capable of detecting a broad range of attacks within seconds.

Read the paper · More papers on PaperTik