Defense approach against application level DDoS attacks based on authentication mechanism

Xu Zhen · Jisuanji gongcheng yu sheji · 2010

The principle and characteristics of application level distributed denial of service attacks are analyzed and a light-weighted authentication mechanism is proposed.An authentication code is embedded in the process of communication between the client and the server.Through client computing,legitimate requests can be correctly distinguished and malicious attacks are filtered.The authentication mechanism is operated between different layers in the network stack.Server-side filtering in the IP layer and client-side computing in the application layer enable low resource consuming and communication transparency to the both sides.The defense approach is implemented on the DDoS mitigation gateway platform.Tests in a realistic environment demonstrate that the approach can defend against attacks effectively and incurs low performance overhead.

Read the paper · More papers on PaperTik