A New Filtering PHF Model to Defend Against DDoS Attacks
Jiangbo Qian · Journal of Ningbo University · 2008
Distributed Denial of Service(DDoS)attacks have been posing more and more threats to cyber security.Among many proposed defending techniques,Path Identification(Pi)is a promising DDoS countermeasure.In the Pi scheme,the victim filters incoming packets based on Pi marks.To defend against DDoS attacks more efficiently,a new filter model is proposed of combining the Pi mark and the hop count(HC).In the proposed model,a victim host identifies and screens out malicious packets based onPi,HCpair.The simulation experiments are conducted on real Internet topology,revealing that the PHF model outperforms the Pi scheme.