MDCI: a Distributed Approach to DDoS Attacks Detection and Response
Jiubin Ju · Journal of Chinese Computer Systems · 2006
Considering the distributed, aggregation nature of Distributed Denial of Service (DDoS) attacks, the data sharing and the cooperative detection among IDS systems distributed in a large scale network is critical important to piece together attack scenario before it aggregated into overwhelming flooding. The cooperative circle model is firstly proposed in MDCI system that means to set up a cooperative defense circle of IDS systems surrounding valuable network assets. With the information exchanging and alerts correlating among sites in the circle, the DDoS attacks can be identified more quickly and accurately. In MDCI system, the packet header contents analysis and backscatter analysis technologies are adopted to identify the attack signature with the information captured locally. The alerts in uniformed format are shared among the cooperative cites and the category probability evaluation method is used to form the overall attack scenarios. Through some experiments, we can conclude that the MDCI system improves detection performance effectively.