A Study on Defense System of Flood Attacks in DDoS
Xue Qiuhua · Microcomputer applications · 2006
This paper presents a defense system(two stage approaches),which has simple and robust approach to defend Flood attacks by observing network traffic.This system firstly monitors SYN count,ratio between SYN and other TCP packets, SYN/ACK count,FIN count,and ratio between ICMP Port Unreach andlCMP packets.And it finds Flood attacks and victims more accurately in the second stage.This system employs MULTOPS structure for finding victims more quickly and accurately.