Design and i mplementation of an IDS against DDOS
Li U · Journal of Changchun University of Technology · 2005
We present an IDS against DDOS.The IDS consisted of at least two pieces andbased on PC class hardware running freely available software components.Sensors locatedbetween an organization's firewall and Internet connection and an analyzer located inside thefirewall.The sensor ran tcpdump to provide a basic sniffer capability.The analyzer fetchedeach hourly tcpdump file fromthe sensor through SSHchannel and then performed analysisusing a set of tcpdump filters fromthe subdirectory filters.Experi mental results showthatthe IDS canidentify DDOS attacks effectively.