A Technique to Make a Path Table for Blocking Distributed Denial-of-Service Attacks
Jee-Sook Eun, Heeyoung Jung · 2015
Generally, there is a Distributed Denial-of-Service (DDoS) detection and defense mechanism in router near the victim host and packet filtering routines are initiated during the attack continues. By the way, it would be better an attack packet blocking mechanism is in router closed to the attacker for downsizing attack traffics in network. This paper presents attack route diagnosis, a technique that operates based on path table. Path table includes routes on a pair of routers identified by route identifier and a packet is delivered with route identifier. If attack is detected by victim, a router near the victim starts attack route diagnosis based on route identifier. This process blocks one attacker at router closed to attacker and which is also not dependent on the number of attacker because of parallel and independent processing. We verify a feasibility of proposed technique on Linux system implementation.