A Collaborative Defense Framework Against DDoS Attacks in Networks

Haiqin Liu · Research Exchange (Washington State University) · 2013

Distributed Denial of Service (DDoS) attacks pose one of the most serious security threats to the Internet.In this work, we aimed to develop a collaborative defense framework against DDoS attacks in networks.We focus on two main phases, which are anomaly detection and filtering of malicious traffic, to achieve a successful defense against DDoS attacks.Our first accomplishment is to effectively detect DDoS traffic at local nodes.Our conducted experiments can be divided into three categories which are described as follows.Firstly, in order to detect the stealthy DDoS attack at an early stage, we proposed an effective detection scheme based on time-series decomposition method.Moreover, in order to more effectively defend against the attacks, our credit-based defense method is designed for pinpointing the malicious flows.In addition, in order to adapt to the high-speed environment, we present a two-level approach for scalable and accurate attack detection by exploiting the asymmetry in the attack traffic.At both detection levels, sketch structures are utilized to ensure the scalability of our scheme.Secondly, current defense systems are not scalable well to high-speed networks and few of them are able to defend against attacks originated from both spoofed and genuine source addresses

Read the paper · More papers on PaperTik