An Active DDoS Defense Model Based on Packet Marking

Yongping Zhang, Zhuqing Wan, Mingming Wu · 2009

In the light of that the defense against DDoS attacks is difficult, an active DDoS defense model based on packet marking is proposed in this paper. The model is composed of the subsystem of the tracking of the attacks and the subsystem of filtering of the attack flows. The function of the former is to reconstruct the attack paths using the information from the marked packets while the function of the later is to filter the attacking packets according to the information obtained from the former. The model has a higher efficiency in reconstructing attack path by using a novel authenticated packet marking scheme for IP trace-back. So, it can correspond to the attack flow in a short time. In addition, flow detection and neural network is also used in the model so that the model is more powerful in the functions of identification and filtering of attack packets and protection of the legitimate flows.

Read the paper · More papers on PaperTik