Application of Neural Network and IP Marking in DDoS Attack Defence
Chao Ma · Jisuanji fangzhen · 2008
DDoS attack, one of the serious menaces to Internet security at present, is originated from DoS attacks. It would be very serious once the network was intruded and attacked by DDoS attack. This attack will cause huge consumption of the resources of network, and block the legitimate traffic. It is diffcult to detect the attack sources because DDoS attacks are distributed on the network. Furthermore these kinds of attacks use IP spoofing, of which fraud IP addresses are forged to hide packer originators and conceal attackers. This attack will cause abnormal traffic and the abnormal traffic will be even obvious when the attack is from distributed sources. So, the approach proposed is to find the network anomalies by using neural network, with the assist of flexible deterministic packer marking. The experimental results show that this approach can be used to defend DDoS attack effectively.