The Study on Defending DDoS Based on Flow Analysis and Dual-Threshold Packet Filtering Policy
Lizhen Shen · Journal of Nanjing University of Posts and Telecommunications · 2007
The disadvantage of DoS(Denial of Service) attacking is to make computers and network unable to provide normal services,which is extremely harmful.Although many solutions to DoS have been developed presently,they are not so consummate.In allusion to the misjudge of current firewall in terms of the attack against DDoS(Distributed Denial of Service),the paper presents a new defending mechanism based on flow analysis and dual-threshold packet filtering,and the mechanism improves the system capability by recording the credible web sites using a communication table and adding intrusion detection.Grounded on the Netfilter framework,the model registers firewall module on NF_IP_PRE_POUTING and fulfils some functions which are the intrusion detection of the usual DoS and the filtering of the abnormal packets being attacked.Finally,the paper provides an experimental environment to test and prove the correlative conclusions.