A Survey on Defending DDos Attack in Router

Qingdong Li · Journal of Nanjing University of Posts and Telecommunications · 2007

Defending DDos attack has always been a key issue in the area of network security.Recently,DDos attack grows quite quickly and the mechanism of defending this faces new challenge.Also methods of defending DDos attack in the router appear accordingly.This paper attempts to survey all those methods and classify them into three typies,including congestion-based methods such as Aggregate Congestion Control(ACC),anomaly-based methods such as Multi-Level Tree for On-line Packet Statistics(MULTOPS),Defend DDos Using Source IP Address Monitoring(SIM) and Normal models of network flows and source-based methods such as Egress filtering,Route-based and IP traceback-based methods.Then it focuses on attack response,including egress filtering,packets filtering and rate limit,and the pushback method.Finally some remarks on defending DDos attack in routers are given.

Read the paper · More papers on PaperTik