Selective Windowed Rate Limiting for DoS Mitigation
Mohammed N. Alenezi, Martin J. Reed, Mohammed A. Alhomidi · 2017 9th IEEE-GCC Conference and Exhibition (GCCCE) · 2017
Denial of service, and in particular distributed denial of service, is a significant challenge for both users and Internet service providers. Common mitigation strategies include filtering and non-discriminatory rate-limiting. However, while these strategies reduce the attack traffic they often negatively affect legitimate user traffic as well. This paper proposes a discriminatory form of rate limiting for a more effective form of mitigation. The discriminatory rate limiting makes use of an efficient data structure, the count-min sketch, to measure the traffic volume from a given source, thus giving the ability to discriminate between high volume attacking sources and lower volume legitimate users. The sketch is applied within a given time window so that it can act on an active attack. The performance of the technique is validated using a simulation in NS-2, and this demonstrates that it is highly effective when compared to non-discriminatory rate limiting and filtering techniques.