Exploring DDoS Defense Mechanisms
Patrick Holl · TU München - Informatik · 2015
Nowadays, Distributed Denial-of-Service (DDoS) attacks are a major threat for all sizes of networks. The number of attacks against companies and institutions steadily increased over the last years. Downtime of an enterprise network usually causes financial damage. Therefore, it is important to have mechanism for DDoS defense. In this paper, various DDoS defense mechanisms are reviewed and compared with focus on rule and model based approaches. Large Botnets allow for new kinds of attacks like flash crowd simulation which mimic a huge mass of organic trac. These kind of attacks are dicult to detect and new defense techniques are required. In order to discover new mitigation algorithms, it is necessary to understand at which layers attacks can happen. Therefore, we take a look on how attacks are classified in current research literature. In addition to the attack classification, rule and model based DDoS defense mechanisms are reviewed. For both model and rule based techniques scenarios exist where one algorithm outperforms the other one. Having this in mind, we list the advantages and drawbacks of both techniques based on insights of research literature. Emerging architectures like SDN may change the way DDoS defense is handled. Researchers are already working on algorithms that are suitable in SDN environments. The goal of this paper is to summarize current defense mechanisms and give a brief outlook on how DDoS defense could look like in the future.