Survey of Low rate Denial of Service (LDoS) attack on RED and its counter strategies
Lija Mohan, M. G. Bijesh, Jyothish K John · 2012
RED Active Queue Management is designed to avoid congestion by controlling the average queue size. Also it avoids TCP global synchronization and provides a bias against burst traffic. But studies show that RED is vulnerable to Shrew attacks. Shrew attack is a Low rate Denial of Service (LDoS) attack, if properly executed could exploit TCP's re-transmission time-out mechanism (RTO) and ultimately reduce its throughput to zero. LDoS attack is very difficult to identify because the average rate of packet sending will be very low. This is achieved by sending large amount of packets for a very short duration and repeating this process in regular intervals. This article analyzes the effect of LDoS attack on TCP as well as RED and compares the existing prevention methods. It also proposes an RED based method to detect and prevent LDoS attacks.