A Defense Framework for Flooding-based DDoS Attacks
Yonghua You · 2007
Distributed denial of service (DDoS) attacks are widely regarded as a major threat to the Internet. A flooding-based DDoS attack is a very common way to attack a victim machine by sending a large amount of malicious traffic. Existing network-level congestion control mechanisms are inadequate in preventing service quality from deteriorating because of these attacks. Although a number of techniques have been proposed to defeat DDoS attacks, it is still hard to detect and respond to flooding-based DDoS attacks due to a large number of attacking machines, the use of source-address spoofing, and the similarities between legitimate and attack traffic. In this thesis, we propose a distributed framework which will help to improve the quality of service of internet service providers (ISP) for legitimate traffic under DDoS attacks. The distributed nature of DDoS problem requires a distributed solution. In this thesis, we propose a distance-based distributed DDoS defense framework which de-fends against attacks by coordinating between the distance-based DDoS defense sys-tems of the source ends and the victim end. The proposed distance-based defense