Synflood Spoofed Source DDoS Attack Defense Based on Packet ID Anomaly Detection with Bloom Filter

Tran Manh Thang, Chi Q. Nguyen, Khanh-Van Nguyen · 2018

TCP SYN Flood is one of the most dangerous types of DDoS attacks. To perform the attack effectively, attackers attempt to send overwhelmed SYN packets with spoofed source, especially, information fields of each packet is spoofed as normal packet. Then it is very difficult to distinguish spoofed packets if we observe individual packet. In the previous study, we proposed method PIDAD (Packet Identification Anomaly Detection) to detect spoofed packets. However, this method has some limitations which is in need of further research and completion. In this study, we propose another method using multiple layers of Bloom Filter to address the limitations of previous our propose.

Read the paper · More papers on PaperTik